Bug #70565 [NEW]: PDO DBLIB MSSql Segmentaion Fault with Prepared Statements
| From: | reyad dot attiyat at gmail dot com | Date: | Wed, 23 Sep 2015 20:00:22 +0000 |
| Subject: | Bug #70565 [NEW]: PDO DBLIB MSSql Segmentaion Fault with Prepared Statements | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-196193@lists.php.net to get a copy of this message | ||
From: reyad dot attiyat at gmail dot com
Operating system: Windows 7
PHP version: 7.0Git-2015-09-23 (Git)
Package: PDO DBlib
Bug Type: Bug
Bug description:PDO DBLIB MSSql Segmentaion Fault with Prepared Statements
Description:
------------
I'm using the latest version of PHP7 master from git compiled on Windows
7 with Visual Studios 2015. The database is MS SQL Server 2014.
I have compiled FreeTDS and the pdo_dblib support, which works fine
except, after several executions of a prepared insert statement (that
may contain UTF-8 characters) a segmentation fault or corrupted SQL
query occurs.
The error seems to be only reproducible when sending UTF-8 characters.
After stepping through the application I have noticed in the file:
https://github.com/php/php-src/blob/master/ext/pdo_dblib/dblib_driver.c
in function:
dblib_handle_quoter()
The quoted string allocation uses emalloc(). This seems to randomly
return a pointer to a previously allocated quoted string. This has
caused both corrupted queries and segmentation faults.
I checked out the code for the other pdo drivers and they use
safe_emalloc() when allocating quoted strings. When I changed the
dblib_handle_quoter() function to use safe_emalloc() instead of
emalloc() the problem goes away.
Test Script:
https://gist.github.com/soda0289/d99fc7e82db8443c7058
--
Edit bug report at https://bugs.php.net/bug.php?id=70565&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=70565&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=70565&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=70565&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=70565&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=70565&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=70565&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=70565&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=70565&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=70565&r=support
Expected behavior: https://bugs.php.net/fix.php?id=70565&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=70565&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=70565&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=70565&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=70565&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=70565&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=70565&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=70565&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=70565&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=70565&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=70565&r=mysqlcfg