Bug #53099 [Com]: mb_ereg_replace uses 100% cpu and takes >10 minutes to execute.

From: Date: Sat, 30 Jul 2016 13:06:33 +0000
Subject: Bug #53099 [Com]: mb_ereg_replace uses 100% cpu and takes >10 minutes to execute.
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-202726@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=53099&edit=1

 ID:                 53099
 Comment by:         ju1ius at laposte dot net
 Reported by:        phpnet at rcpt dot at
 Summary:            mb_ereg_replace uses 100% cpu and takes >10 minutes
                     to execute.
 Status:             Assigned
 Type:               Bug
 Package:            mbstring related
 Operating System:   Ubuntu 9.10
 PHP Version:        5.3.3
 Assigned To:        moriyoshi
 Block user comment: N
 Private report:     N

 New Comment:

This is not a bug, this is catastrophic backtracking.
http://www.regular-expressions.info/catastrophic.html

The second pattern in your function is problematic:
(\s|\t|\n\r)*$
All regexps engines will choke on that.


Previous Comments:
------------------------------------------------------------------------
[2016-07-30 11:34:00] cmb@php.net

Related To: Bug #60664

------------------------------------------------------------------------
[2010-10-19 12:52:43] phpnet at rcpt dot at

Thanks felipe, sorry about that; to avoid confusion, I mean 'mb_ereg_replace' not
'ereg_replace'.

------------------------------------------------------------------------
[2010-10-18 22:32:40] felipe@php.net

s/ereg_replace/mb_ereg_replace/g :)

------------------------------------------------------------------------
[2010-10-18 17:28:09] phpnet at rcpt dot at

Description:
------------
I have written a mb_trim function in php which uses ereg_replace to trim strings in the same manner
as trim() does.

The function is available at http://php.net/manual/en/ref.mbstring.php
Under the heading 'phpnet at rcpt dot at - 19-Aug-2010 02:46'

Using the string excerpt from our production environment (http://pastebin.com/wmyjPmBV),
ereg_replace appears to enter some sort of recursive loop, in my environment it takes 100% cpu for
20 minutes before finally returning the correct result.

When the section which reads: array( "\s","\t","\n","\r",
"\0", "\x0B" )

...is changed to array( "\s", "\0", "\x0B" ) then ereg_replace returns
promptly with the correct result.



Test script:
---------------
The function is available at http://php.net/manual/en/ref.mbstring.php
Under the heading 'phpnet at rcpt dot at - 19-Aug-2010 02:46'

It is also available here:
http://pastebin.com/CCpaVXay

The (serialized) string that causes the problem is:
s:488:"<I>Swans	</I>																						Wisely moving from the middle of July to
the middle of autumn, this indoor, forward-thinking avant-rock weekend brings together all sorts of
fiercely experimental noisemakers, from psychedelic-folk to death metal, with a hotly anticipated
headline set from Michael Gira's New York noise inspiration Swans. Don't expect many
stony-faced rock nerds, though. The organisers serve tea and cake throughout and they're
promising other fun and games this year.";


It is also available for download here:
http://pastebin.com/wmyjPmBV

You can execute the script with the following syntax:
<?php mb_trim( $string );

Expected result:
----------------
PHP will return the correct result quickly.

Actual result:
--------------
PHP will run at 100% CPU for 20 minutes.


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=53099&edit=1


Thread (6 messages)

« previous php.bugs (#202726) next »