Bug #70565 [Com]: PDO DBLIB MSSql Segmentaion Fault with Prepared Statements
| From: | reyad dot attiyat at gmail dot com | Date: | Thu, 24 Sep 2015 14:16:13 +0000 |
| Subject: | Bug #70565 [Com]: PDO DBLIB MSSql Segmentaion Fault with Prepared Statements | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-196213@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=70565&edit=1
ID: 70565
Comment by: reyad dot attiyat at gmail dot com
Reported by: reyad dot attiyat at gmail dot com
Summary: PDO DBLIB MSSql Segmentaion Fault with Prepared
Statements
Status: Open
Type: Bug
Package: PDO DBlib
Operating System: Windows 7
PHP Version: 7.0Git-2015-09-23 (Git)
Block user comment: N
Private report: N
New Comment:
I have changed the test script to not use utf-8 chars but instead just pass a 0 and same
segmentation fault occurs during allocation.
Backtrace:
php7ts.dll!_emalloc(unsigned __int64 size) Line 2414 C
php7ts.dll!dblib_handle_quoter(_pdo_dbh_t * dbh, const char * unquoted, unsigned __int64
unquotedlen, char * * quoted, unsigned __int64 * quotedlen, pdo_param_type paramtype) Line 184 C
php7ts.dll!pdo_parse_params(_pdo_stmt_t * stmt, char * inquery, unsigned __int64 inquery_len, char
* * outquery, unsigned __int64 * outquery_len) Line 263 C
php7ts.dll!zim_PDOStatement_execute(_zend_execute_data * execute_data, _zval_struct *
return_value) Line 495 C
php7ts.dll!ZEND_DO_FCALL_SPEC_HANDLER(_zend_execute_data * execute_data) Line 850 C
php7ts.dll!execute_ex(_zend_execute_data * ex) Line 413 C
php7ts.dll!zend_execute(_zend_op_array * op_array, _zval_struct * return_value) Line 455 C
php7ts.dll!zend_execute_scripts(int type, _zval_struct * retval, int file_count, ...) Line 1429 C
php7ts.dll!php_execute_script(_zend_file_handle * primary_file) Line 2471 C
php.exe!do_cli(int argc, char * * argv) Line 972 C
php.exe!main(int argc, char * * argv) Line 1342 C
Previous Comments:
------------------------------------------------------------------------
[2015-09-23 20:17:25] reyad dot attiyat at gmail dot com
Also noticed in PHP 5.16 code they use safe_emalloc() in the dblib_handle_quoter() function.
https://github.com/php/php-src/blob/PHP-5.6.14/ext/pdo_dblib/dblib_driver.c
------------------------------------------------------------------------
[2015-09-23 20:07:30] reyad dot attiyat at gmail dot com
Might be related to BUG #67495
------------------------------------------------------------------------
[2015-09-23 20:00:21] reyad dot attiyat at gmail dot com
Description:
------------
I'm using the latest version of PHP7 master from git compiled on Windows 7 with Visual Studios
2015. The database is MS SQL Server 2014.
I have compiled FreeTDS and the pdo_dblib support, which works fine except, after several executions
of a prepared insert statement (that may contain UTF-8 characters) a segmentation fault or corrupted
SQL query occurs.
The error seems to be only reproducible when sending UTF-8 characters.
After stepping through the application I have noticed in the file:
https://github.com/php/php-src/blob/master/ext/pdo_dblib/dblib_driver.c
in function:
dblib_handle_quoter()
The quoted string allocation uses emalloc(). This seems to randomly return a pointer to a previously
allocated quoted string. This has caused both corrupted queries and segmentation faults.
I checked out the code for the other pdo drivers and they use safe_emalloc() when allocating quoted
strings. When I changed the dblib_handle_quoter() function to use safe_emalloc() instead of
emalloc() the problem goes away.
Test Script:
https://gist.github.com/soda0289/d99fc7e82db8443c7058
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=70565&edit=1