Bug #67297 [Opn->Fbk]: Pdo-MySql Insert (escaping) bug

From: Date: Sat, 20 Aug 2016 13:15:57 +0000
Subject: Bug #67297 [Opn->Fbk]: Pdo-MySql Insert (escaping) bug
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-203414@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=67297&edit=1 ID: 67297 Updated by: cmb@php.net Reported by: genuser at gmx dot net Summary: Pdo-MySql Insert (escaping) bug -Status: Open +Status: Feedback Type: Bug Package: PCRE related Operating System: Debian GNU/Linux 7.5 (wheezy) PHP Version: 5.5.12 -Assigned To: +Assigned To: cmb Block user comment: N Private report: N New Comment: Thank you for this bug report. To properly diagnose the problem, we need a short but complete example script to be able to reproduce this bug ourselves. A proper reproducing script starts with , is max. 10-20 lines long and does not require any external resources such as databases, etc. If the script requires a database to demonstrate the issue, please make sure it creates all necessary tables, stored procedures etc. Please avoid embedding huge scripts into the report. Previous Comments: ------------------------------------------------------------------------ [2014-05-17 11:41:09] genuser at gmx dot net Description: ------------ Hey there, php running into an segmentation fault. I try to insert a json record into my database and mybe pcre become a problem by escaping? Test script: --------------- I'm try to import this by Mysql Pdo. Example-Part of sql insert: '{\"WahlartenLang\":\"\",\"WahlartenKurz\":\"RG,KT,GR,GR+\",\"PostfreimachungVersandta\":\"0\",\"Wahlkreisnummer\":\"09\",\"Wahlbezirksnummer\":\"05041\",\"Waehlernummer\":\"110\",\"Familienname\":\"Schm\\u00f6lling\",\"Vorname\":\"Patrick\",\"Strassenschluessel\":\"76018\", ............ Expected result: ---------------- Successful database insert and no segmentation fault. Actual result: -------------- ============================= Program received signal SIGSEGV, Segmentation fault. ============================= 0x000000000048343b in match (eptr=0x18257d2 "785);\n;", ecode=0x122b797 "\035\"x", mstart=0x1822719 "\"WahlartenLang\\\":\\\"\\\",\\\"WahlartenKurz\\\":\\\"RG,KT,GR,GR+\\\",\\\"PostfreimachungVersandta\\\":\\\"0\\\",\\\"Wahlkreisnummer\\\":\\\"09\\\",\\\"Wahlbezirksnummer\\\":\\\"05041\\\",\\\"Waehlernummer\\\":\\\"110\\\",\\\"Familienname\\\":\\\"Schm"..., offset_top=4, md=0x7fffffff90a0, eptrb=0x0, rdepth=10890) at /usr/src/php5.5/source/php5-5.5.12/ext/pcre/pcrelib/pcre_exec.c:1802 1802 /usr/src/php5.5/source/php5-5.5.12/ext/pcre/pcrelib/pcre_exec.c: Datei oder Verzeichnis nicht gefunden. ============================= Part of Backtrace ============================= #0 0x000000000048343b in match (eptr=0x18257d2 "785);\n;", ecode=0x122b797 "\035\"x", mstart=0x1822719 "\"WahlartenLang\\\":\\\"\\\",\\\"WahlartenKurz\\\":\\\"RG,KT,GR,GR+\\\",\\\"PostfreimachungVersandta\\\":\\\"0\\\",\\\"Wahlkreisnummer\\\":\\\"09\\\",\\\"Wahlbezirksnummer\\\":\\\"05041\\\",\\\"Waehlernummer\\\":\\\"110\\\",\\\"Familienname\\\":\\\"Schm"..., offset_top=4, md=0x7fffffff90a0, eptrb=0x0, rdepth=10890) at /usr/src/php5.5/source/php5-5.5.12/ext/pcre/pcrelib/pcre_exec.c:1802 #1 0x0000000000493f0e in match (eptr=0x18257d2 "785);\n;", ecode=0x122b794 "z", mstart=0x1822719 "\"WahlartenLang\\\":\\\"\\\",\\\"WahlartenKurz\\\":\\\"RG,KT,GR,GR+\\\",\\\"PostfreimachungVersandta\\\":\\\"0\\\",\\\"Wahlkreisnummer\\\":\\\"09\\\",\\\"Wahlbezirksnummer\\\":\\\"05041\\\",\\\"Waehlernummer\\\":\\\"110\\\",\\\"Familienname\\\":\\\"Schm"..., offset_top=4, md=<optimized out>, eptrb=0x0, rdepth=10889) at /usr/src/php5.5/source/php5-5.5.12/ext/pcre/pcrelib/pcre_exec.c:2024 . . . . . #10891 0x000000000049524f in php_pcre_exec (argument_re=0x122b740, extra_data=extra_data@entry=0x7fffffff9310, subject=subject@entry=0x18226c0 "INSERT INTO job_detail \n(job_id, print_id, state_date, record, state_id) \nVALUES \n(,,,'{\\\"WahlartenLang\\\":\\\"\\\",\\\"WahlartenKurz\\\":\\\"RG,KT,GR,GR+\\\",\\\"PostfreimachungVersandta\\\":\\\"0\\\",\\\"Wahlkreisnummer\\\""..., length=length@entry=12569, start_offset=start_offset@entry=0, options=0, offsets=offsets@entry=0x142ba28, offsetcount=offsetcount@entry=6) at /usr/src/php5.5/source/php5-5.5.12/ext/pcre/pcrelib/pcre_exec.c:6945 #10892 0x000000000049aed3 in php_pcre_replace_impl (pce=0x122b820, subject=0x18226c0 "INSERT INTO job_detail \n(job_id, print_id, state_date, record, state_id) \nVALUES \n(,,,'{\\\"WahlartenLang\\\":\\\"\\\",\\\"WahlartenKurz\\\":\\\"RG,KT,GR,GR+\\\",\\\"PostfreimachungVersandta\\\":\\\"0\\\",\\\"Wahlkreisnummer\\\""..., subject_len=12569, replace_val=replace_val@entry=0x17d1a20, is_callable_replace=is_callable_replace@entry=0, result_len=0x7fffffff9450, limit=-1, replace_count=0x7fffffff9454) at /usr/src/php5.5/source/php5-5.5.12/ext/pcre/php_pcre.c:1091 #10893 0x000000000049bc5f in php_pcre_replace (regex=<optimized out>, regex_len=<optimized out>, subject=<optimized out>, subject_len=<optimized out>, replace_val=replace_val@entry=0x17d1a20, is_callable_replace=is_callable_replace@entry=0, result_len=0x7fffffffffff, result_len@entry=0x7fffffff9450, limit=-27564, limit@entry=-1, replace_count=replace_count@entry=0x7fffffff9454) at /usr/src/php5.5/source/php5-5.5.12/ext/pcre/php_pcre.c:997 ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=67297&edit=1

« previous php.bugs (#203414) next »