Bug #70565 [Com]: PDO DBLIB MSSql Segmentaion Fault with Prepared Statements

From: Date: Thu, 24 Sep 2015 14:16:13 +0000
Subject: Bug #70565 [Com]: PDO DBLIB MSSql Segmentaion Fault with Prepared Statements
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-196213@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70565&edit=1 ID: 70565 Comment by: reyad dot attiyat at gmail dot com Reported by: reyad dot attiyat at gmail dot com Summary: PDO DBLIB MSSql Segmentaion Fault with Prepared Statements Status: Open Type: Bug Package: PDO DBlib Operating System: Windows 7 PHP Version: 7.0Git-2015-09-23 (Git) Block user comment: N Private report: N New Comment: I have changed the test script to not use utf-8 chars but instead just pass a 0 and same segmentation fault occurs during allocation. Backtrace: php7ts.dll!_emalloc(unsigned __int64 size) Line 2414 C php7ts.dll!dblib_handle_quoter(_pdo_dbh_t * dbh, const char * unquoted, unsigned __int64 unquotedlen, char * * quoted, unsigned __int64 * quotedlen, pdo_param_type paramtype) Line 184 C php7ts.dll!pdo_parse_params(_pdo_stmt_t * stmt, char * inquery, unsigned __int64 inquery_len, char * * outquery, unsigned __int64 * outquery_len) Line 263 C php7ts.dll!zim_PDOStatement_execute(_zend_execute_data * execute_data, _zval_struct * return_value) Line 495 C php7ts.dll!ZEND_DO_FCALL_SPEC_HANDLER(_zend_execute_data * execute_data) Line 850 C php7ts.dll!execute_ex(_zend_execute_data * ex) Line 413 C php7ts.dll!zend_execute(_zend_op_array * op_array, _zval_struct * return_value) Line 455 C php7ts.dll!zend_execute_scripts(int type, _zval_struct * retval, int file_count, ...) Line 1429 C php7ts.dll!php_execute_script(_zend_file_handle * primary_file) Line 2471 C php.exe!do_cli(int argc, char * * argv) Line 972 C php.exe!main(int argc, char * * argv) Line 1342 C Previous Comments: ------------------------------------------------------------------------ [2015-09-23 20:17:25] reyad dot attiyat at gmail dot com Also noticed in PHP 5.16 code they use safe_emalloc() in the dblib_handle_quoter() function. https://github.com/php/php-src/blob/PHP-5.6.14/ext/pdo_dblib/dblib_driver.c ------------------------------------------------------------------------ [2015-09-23 20:07:30] reyad dot attiyat at gmail dot com Might be related to BUG #67495 ------------------------------------------------------------------------ [2015-09-23 20:00:21] reyad dot attiyat at gmail dot com Description: ------------ I'm using the latest version of PHP7 master from git compiled on Windows 7 with Visual Studios 2015. The database is MS SQL Server 2014. I have compiled FreeTDS and the pdo_dblib support, which works fine except, after several executions of a prepared insert statement (that may contain UTF-8 characters) a segmentation fault or corrupted SQL query occurs. The error seems to be only reproducible when sending UTF-8 characters. After stepping through the application I have noticed in the file: https://github.com/php/php-src/blob/master/ext/pdo_dblib/dblib_driver.c in function: dblib_handle_quoter() The quoted string allocation uses emalloc(). This seems to randomly return a pointer to a previously allocated quoted string. This has caused both corrupted queries and segmentation faults. I checked out the code for the other pdo drivers and they use safe_emalloc() when allocating quoted strings. When I changed the dblib_handle_quoter() function to use safe_emalloc() instead of emalloc() the problem goes away. Test Script: https://gist.github.com/soda0289/d99fc7e82db8443c7058 ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=70565&edit=1

« previous php.bugs (#196213) next »