#18422 [Fbk->Csd]: emalloc() call crashes Apache (backtrace provided)
| From: | sniper@php.net | Date: | Wed, 11 Sep 2002 16:43:13 +0000 |
| Subject: | #18422 [Fbk->Csd]: emalloc() call crashes Apache (backtrace provided) | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-19149@lists.php.net to get a copy of this message | ||
ID: 18422
Updated by: sniper@php.net
Reported By: acs@hourglassone.com
-Status: Feedback
+Status: Closed
Bug Type: Reproducible crash
Operating System: Redhat Linux 7.2
PHP Version: 4.2.1
New Comment:
No feedback..should be fixed in 4.2.3 though.
Previous Comments:
------------------------------------------------------------------------
[2002-07-18 19:25:31] sniper@php.net
If it's not fixed in the snapshot (might not be) please
provide us the patch against it (diff -u) and add it here..
------------------------------------------------------------------------
[2002-07-18 18:52:23] acs@hourglassone.com
More info: I managed to solve the problem by applying the following:
593,595c593,595
<
< add_next_index_stringl(return_value, strp, size, 1);
<
---
> if (size > 0) {
> add_next_index_stringl(return_value, strp, size, 1);
> }
Don't know if this is a good solution or not. I will try the latest
snapshot tomorrow and see if the problem is solved.
Cheers.
------------------------------------------------------------------------
[2002-07-18 17:52:48] sniper@php.net
Firs try this snapshot:
http://snaps.php.net/php4-latest.tar.gz
And if it does not work, give a short, complete and standalone script
which can easily be used to reproduce this. As it seems the crash
happens in split(), come up with such script that does NOT include
anything but it and the data that crashes it.
------------------------------------------------------------------------
[2002-07-18 17:06:15] acs@hourglassone.com
Looks like you're correct.. I added a trim() around the second
paramater of split() and it seems to take care of it.
It would seem that there's no checking done on the size parameter in
php_split before calling add_next_index_stringl for the last value.
line number is ext/standard/reg.c:574 in php4.2.2dev
Snippet of code (offending line marked by >>>> <<<<), $sHeader is
returned by curl_exec):
class HeaderObj {
function HeaderObj($sHeader) {
$this->header = $sHeader;
$aHeaders = Array();
>>>>
$aLines = split("\n",$sHeader);
<<<<
foreach($aLines as $sLine) {
$temp = split(":",trim($sLine));
$aHeaders[$temp[0]] = (isset($temp[1])) ? trim($temp[1]) : "";
if ($temp[0] == "Content-Type") {
if (!isset($temp[1])) {
$aHeaders[$temp[0]] = trim("text/html");
}
}
}
if (!isset($aHeaders['Content-Type'])) {
$aHeaders['Content-Type'] = "text/html";
}
$this->headers = $aHeaders;
$this->headers['string'] = $sHeader;
reset($this->headers);
}
}
---
If I put it in a trim(), with --enable-debug, I get this warning:
<b>Warning</b>: String is not zero-terminated (HTTP/1.1 200 OK
Date: Thu, 18 Jul 2002 20:58:13 GMT
Server: Apache/1.3.23 (Unix)
Last-Modified: Fri, 28 Jun 2002 23:00:30 GMT
ETag: "736-3d1cea8e"
Accept-Ranges: bytes
Content-Length: 1846
Content-Type: application/x-javascript
Toolbar=search; siteinfopopup=siteinfo; relatedlinkspopup=relatedlinks;
twym=webyoumade; searchMethod=Yahoo; twym_disabled=false;
ALXSID=ccd89a2e038361a7cb25c7f27130ed86;
twym65=D4ABCAC7DEF19AA7979F60CED1A3%2521D7AED1C9EBED9CA59DA7A6DE9099A2E7%2521DB6C8FD3EBE1%2521C5ACD5C5E5DBAF9CA7AB9399C4A5ABA8A89D%2521D1B2D4D5E5A89CA2A1;
aid=iKy4Z0eeh000NE
Host: client.alexa.com:2222
Pragma: no-cache
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, */*
Referer: http://client.alexa.com/speed_test/index.html
Accept-Language: en-us
@) (source: zend_execute_API.c:274) in <b>Unknown</b> on line
<b>0</b><br />
------------------------------------------------------------------------
[2002-07-18 16:31:05] derick@php.net
It crashes on a split function, can you try to shorten your script to
narrow the search for us?
Derick
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
http://bugs.php.net/18422
--
Edit this bug report at http://bugs.php.net/?id=18422&edit=1