Bug #71049 [Opn]: SQLite3Stmt::execute() releases bound parameter instead of internal buffer
| From: | sustmidown at centrum dot cz | Date: | Mon, 07 Dec 2015 12:35:46 +0000 |
| Subject: | Bug #71049 [Opn]: SQLite3Stmt::execute() releases bound parameter instead of internal buffer | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-197659@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=71049&edit=1
ID: 71049
User updated by: sustmidown at centrum dot cz
Reported by: sustmidown at centrum dot cz
Summary: SQLite3Stmt::execute() releases bound parameter
instead of internal buffer
Status: Open
Type: Bug
Package: SQLite related
-Operating System:
+Operating System: Linux x86-64
PHP Version: 7.0.0
Block user comment: N
Private report: N
New Comment:
EDIT: OS: Linux x86-64
Previous Comments:
------------------------------------------------------------------------
[2015-12-07 12:33:11] sustmidown at centrum dot cz
Description:
------------
In commit 352117b728cd3edb8b79c7ec4e45ae060224b6ad
(https://github.com/php/php-src/commit/352117b728cd3edb8b79c7ec4e45ae060224b6ad) there was a change
of condition which checked whether to call:
zend_string_release(buffer);
from:
if (stream) {
to:
if (buffer) {
The problem is that buffer can point either to zend_string allocated in by php_stream_copy_to_mem()
or to value of the bound parameter.
If the parameter is not a resource, buffer points to the value of the bound parameter and therefore
it is released which later causes memory corruption and SIGSEGV - Segmentation fault.
With the supplied patch my test configuration runs OK. (I am sorry I cannot provide a test script,
but its a bunch of unit tests run in PHP unit using SQLite as Doctrine metadata and DQL query
cache.)
Expected result:
----------------
SQLite3Stmt::execute() should call zend_string_release() only on buffer containing result from
php_stream_copy_to_mem().
Actual result:
--------------
SQLite3Stmt::execute() calls zend_string_release() on buffer containing Z_STR_P(parameter).
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=71049&edit=1