Bug #69528 [Opn]: MBString making Apache crash

From: Date: Fri, 22 May 2015 13:58:41 +0000
Subject: Bug #69528 [Opn]: MBString making Apache crash
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-192827@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69528&edit=1

 ID:                 69528
 User updated by:    jfha73 at gmail dot com
 Reported by:        jfha73 at gmail dot com
 Summary:            MBString making Apache crash
 Status:             Open
 Type:               Bug
 Package:            mbstring related
 Operating System:   Windows
-PHP Version:        5.6.8
+PHP Version:        5.6.9
 Block user comment: N
 Private report:     N

 New Comment:

Hey guys,

Is this an OsTicket problem or MBString extension?

They just release a new version of the ticket system and it still made my apache crash with the same
php_mbstring.dll error.

Thanks.


Previous Comments:
------------------------------------------------------------------------
[2015-05-05 17:29:25] jfha73 at gmail dot com

By the way, this is the ticket with osTicket.

https://github.com/osTicket/osTicket-1.8/issues/2008

------------------------------------------------------------------------
[2015-05-05 17:28:28] jfha73 at gmail dot com

I doubled the ThreadStackSize to 131072 and it still crashed, it worked a little better though.

I opened a ticket with osTicket, they also asked me to add this to the directory where osTicket was
installed and nothing.

php_admin_value mbstring.func_overload 0

------------------------------------------------------------------------
[2015-05-04 06:52:18] ab@php.net

Installed osTicket and here's the backtrace I've got

....................................
 	php5ts_debug.dll!match(const unsigned char * eptr, const unsigned char * ecode, const unsigned
char * mstart, int offset_top, match_data * md, eptrblock * eptrb, unsigned int rdepth) Line 2061	C
 	php5ts_debug.dll!match(const unsigned char * eptr, const unsigned char * ecode, const unsigned
char * mstart, int offset_top, match_data * md, eptrblock * eptrb, unsigned int rdepth) Line 2061	C
 	php5ts_debug.dll!match(const unsigned char * eptr, const unsigned char * ecode, const unsigned
char * mstart, int offset_top, match_data * md, eptrblock * eptrb, unsigned int rdepth) Line 1878	C
 	php5ts_debug.dll!match(const unsigned char * eptr, const unsigned char * ecode, const unsigned
char * mstart, int offset_top, match_data * md, eptrblock * eptrb, unsigned int rdepth) Line 1541	C
 	php5ts_debug.dll!php_pcre_exec(const real_pcre * argument_re, const pcre_extra * extra_data, const
char * subject, int length, int start_offset, int options, int * offsets, int offsetcount) Line
6935	C
 	php5ts_debug.dll!php_pcre_split_impl(pcre_cache_entry * pce, char * subject, int subject_len,
_zval_struct * return_value, long limit_val, long flags, void * * * tsrm_ls) Line 1580	C
 	php5ts_debug.dll!zif_preg_split(int ht, _zval_struct * return_value, _zval_struct * *
return_value_ptr, _zval_struct * this_ptr, int return_value_used, void * * * tsrm_ls) Line 1515	C
 	php5ts_debug.dll!zend_do_fcall_common_helper_SPEC(_zend_execute_data * execute_data, void * * *
tsrm_ls) Line 559	C
 	php5ts_debug.dll!ZEND_DO_FCALL_SPEC_CONST_HANDLER(_zend_execute_data * execute_data, void * * *
tsrm_ls) Line 2600	C
 	php5ts_debug.dll!execute_ex(_zend_execute_data * execute_data, void * * * tsrm_ls) Line 363	C
 	php5ts_debug.dll!zend_execute(_zend_op_array * op_array, void * * * tsrm_ls) Line 389	C
 	php5ts_debug.dll!zend_execute_scripts(int type, void * * * tsrm_ls, _zval_struct * * retval, int
file_count, ...) Line 1342	C
 	php5ts_debug.dll!php_execute_script(_zend_file_handle * primary_file, void * * * tsrm_ls) Line
2597	C
 	php5apache2_4.dll!00007ff84cab66d0()	Unknown

The exception happens already when installing and is a stack overflow in PCRE. This is a usual thing
with PCRE when too much recursion is caused. I don't think there's something to do about
this right now, maybe trying to upgrade to PCRE 8.37 . But I guess it's a good thing anyway
anyway to file a ticket for osTicket :) ... the arguments for the preg_split call are:

regex "/;(?=(?:[^']*'[^']*')*[^']*$)/"
subject "\nDROP TABLE IF EXISTS ost_api_key;\nCREATE TABLE
ost_api_key (\n  id int(10) unsigned NOT NULL auto_increment,\n 
isactive tinyint(1) NOT NULL default '1',\n  ipaddr varchar(64)
NOT NULL,\n  `api... 

subject length happens to be of 31305 bytes

limit -1
flags 0

There could be also an mbstring issue as you say, but ATM i don't come through to it.

What you could also try is increasing the stack size for your Apache binary, then lets see further.

Thanks.

------------------------------------------------------------------------
[2015-04-30 14:21:45] jfha73 at gmail dot com

I forgot to include that I downloaded the open source version of osTicket version 1.9.7

------------------------------------------------------------------------
[2015-04-29 13:27:28] jfha73 at gmail dot com

I just added my httpd.conf and httpd-vhosts.conf so you can check it out, only domain has been
changed.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=69528


--
Edit this bug report at https://bugs.php.net/bug.php?id=69528&edit=1


Thread (17 messages)

« previous php.bugs (#192827) next »