Bug #71049 [NEW]: SQLite3Stmt::execute() releases bound parameter instead of internal buffer
| From: | sustmidown at centrum dot cz | Date: | Mon, 07 Dec 2015 12:33:12 +0000 |
| Subject: | Bug #71049 [NEW]: SQLite3Stmt::execute() releases bound parameter instead of internal buffer | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-197658@lists.php.net to get a copy of this message | ||
From: sustmidown at centrum dot cz
Operating system:
PHP version: 7.0.0
Package: SQLite related
Bug Type: Bug
Bug description:SQLite3Stmt::execute() releases bound parameter instead of internal buffer
Description:
------------
In commit 352117b728cd3edb8b79c7ec4e45ae060224b6ad
(https://github.com/php/php-src/commit/352117b728cd3edb8b79c7ec4e45ae060224b6ad)
there was a change of condition which checked whether to call:
zend_string_release(buffer);
from:
if (stream) {
to:
if (buffer) {
The problem is that buffer can point either to zend_string allocated in
by php_stream_copy_to_mem() or to value of the bound parameter.
If the parameter is not a resource, buffer points to the value of the
bound parameter and therefore it is released which later causes memory
corruption and SIGSEGV - Segmentation fault.
With the supplied patch my test configuration runs OK. (I am sorry I
cannot provide a test script, but its a bunch of unit tests run in PHP
unit using SQLite as Doctrine metadata and DQL query cache.)
Expected result:
----------------
SQLite3Stmt::execute() should call zend_string_release() only on buffer
containing result from php_stream_copy_to_mem().
Actual result:
--------------
SQLite3Stmt::execute() calls zend_string_release() on buffer containing
Z_STR_P(parameter).
--
Edit bug report at https://bugs.php.net/bug.php?id=71049&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=71049&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=71049&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=71049&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=71049&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=71049&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=71049&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=71049&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=71049&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=71049&r=support
Expected behavior: https://bugs.php.net/fix.php?id=71049&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=71049&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=71049&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=71049&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=71049&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=71049&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=71049&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=71049&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=71049&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=71049&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=71049&r=mysqlcfg