Bug #71049 [NEW]: SQLite3Stmt::execute() releases bound parameter instead of internal buffer

From: Date: Mon, 07 Dec 2015 12:33:12 +0000
Subject: Bug #71049 [NEW]: SQLite3Stmt::execute() releases bound parameter instead of internal buffer
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-197658@lists.php.net to get a copy of this message
From: sustmidown at centrum dot cz Operating system: PHP version: 7.0.0 Package: SQLite related Bug Type: Bug Bug description:SQLite3Stmt::execute() releases bound parameter instead of internal buffer Description: ------------ In commit 352117b728cd3edb8b79c7ec4e45ae060224b6ad (https://github.com/php/php-src/commit/352117b728cd3edb8b79c7ec4e45ae060224b6ad) there was a change of condition which checked whether to call: zend_string_release(buffer); from: if (stream) { to: if (buffer) { The problem is that buffer can point either to zend_string allocated in by php_stream_copy_to_mem() or to value of the bound parameter. If the parameter is not a resource, buffer points to the value of the bound parameter and therefore it is released which later causes memory corruption and SIGSEGV - Segmentation fault. With the supplied patch my test configuration runs OK. (I am sorry I cannot provide a test script, but its a bunch of unit tests run in PHP unit using SQLite as Doctrine metadata and DQL query cache.) Expected result: ---------------- SQLite3Stmt::execute() should call zend_string_release() only on buffer containing result from php_stream_copy_to_mem(). Actual result: -------------- SQLite3Stmt::execute() calls zend_string_release() on buffer containing Z_STR_P(parameter). -- Edit bug report at https://bugs.php.net/bug.php?id=71049&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=71049&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=71049&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=71049&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=71049&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=71049&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=71049&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=71049&r=needscript Try newer version: https://bugs.php.net/fix.php?id=71049&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=71049&r=support Expected behavior: https://bugs.php.net/fix.php?id=71049&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=71049&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=71049&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=71049&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=71049&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=71049&r=dst IIS Stability: https://bugs.php.net/fix.php?id=71049&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=71049&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=71049&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=71049&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=71049&r=mysqlcfg

« previous php.bugs (#197658) next »