Bug #68396 [Fbk->NoF]: iconv null pointer write with zend_mm
| From: | php-bugs at lists dot php dot net | Date: | Sun, 21 Aug 2016 04:22:24 +0000 |
| Subject: | Bug #68396 [Fbk->NoF]: iconv null pointer write with zend_mm | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-203434@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=68396&edit=1
ID: 68396
Updated by: php-bugs@lists.php.net
Reported by: mattficken@php.net
Summary: iconv null pointer write with zend_mm
-Status: Feedback
+Status: No Feedback
Type: Bug
Package: CGI/CLI related
Operating System: Windows
PHP Version: 5.5.18
Assigned To: cmb
Private report: N
New Comment:
No feedback was provided. The bug is being suspended because
we assume that you are no longer experiencing the problem.
If this is not the case and you are able to provide the
information that was requested earlier, please do so and
change the status of the bug back to "Re-Opened". Thank you.
Previous Comments:
------------------------------------------------------------------------
[2016-08-08 12:22:39] cmb@php.net
I'm afraid this issue can't be resolved without a reproduce script
or at the very least a more meaningful stack backtrace. Can you
still get one, Matt?
------------------------------------------------------------------------
[2014-11-11 09:04:39] mattficken@php.net
Description:
------------
Actually PHP Version: 5.5.13 <could be any more recent version>
Event: NULL_CLASS_PTR_WRITE 0xc0000005 in php5.dll
SAPI: php-cgi.exe
OS: Windows 7.0, 8.0, mostly French and Chinese LCIDs
The fact it happens in 5 different threads suggests it may not be fault of iconv ext, instead could
be some other threading/mm issue in core providing iconv an invalid pointer which it uses at the the
right/wrong time to cause crash.
Stack traces of user-mode application crashes on Windows can (with user consent) be reported to
Microsoft (see Windows Error Reporting and Watson). This bug is based on one of those reports.
Note: can request additional information including memory dumps to help investigate this issue
further.
Watson #73491156297
Actual result:
--------------
NOTE:
aaaaaaaa indicates NULL, indicates either stack corruption or some frames missing
due to dump -> minidump conversion
Thread 0
01bd84ac aaaaaaaa php5!_zend_mm_free_int+0x2ae
[c:\php-sdk\php55\vc11\x86\php-5.5.13\zend\zend_alloc.c @ 2110]
01bd84b0 01000000 0xaaaaaaaa
01bd84b4 aaaaaaaa iconv+0x20000
01bd84b8 aaaaaaaa 0xaaaaaaaa
01bd84bc 00000000 0xaaaaaaaa
Thread 1
01bd84ac aaaaaaaa php5!_zend_mm_free_int+0x2ae
[c:\php-sdk\php55\vc11\x86\php-5.5.13\zend\zend_alloc.c @ 2110]
01bd84b0 01000000 0xaaaaaaaa
01bd84b4 aaaaaaaa iconv+0x20000
01bd84b8 aaaaaaaa 0xaaaaaaaa
01bd84bc 00000000 0xaaaaaaaa
Thread 2
01bd84ac aaaaaaaa php5!_zend_mm_free_int+0x2ae
[c:\php-sdk\php55\vc11\x86\php-5.5.13\zend\zend_alloc.c @ 2110]
01bd84b0 01000000 0xaaaaaaaa
01bd84b4 aaaaaaaa iconv+0x20000
01bd84b8 aaaaaaaa 0xaaaaaaaa
01bd84bc 00000000 0xaaaaaaaa
Thread 3
01bd84ac aaaaaaaa php5!_zend_mm_free_int+0x2ae
[c:\php-sdk\php55\vc11\x86\php-5.5.13\zend\zend_alloc.c @ 2110]
01bd84b0 01000000 0xaaaaaaaa
01bd84b4 aaaaaaaa iconv+0x20000
01bd84b8 aaaaaaaa 0xaaaaaaaa
01bd84bc 00000000 0xaaaaaaaa
Thread 4
01bd84ac aaaaaaaa php5!_zend_mm_free_int+0x2ae
[c:\php-sdk\php55\vc11\x86\php-5.5.13\zend\zend_alloc.c @ 2110]
01bd84b0 01000000 0xaaaaaaaa
01bd84b4 aaaaaaaa iconv+0x20000
01bd84b8 aaaaaaaa 0xaaaaaaaa
01bd84bc 00000000 0xaaaaaaaa
Thread 5
01bd84ac aaaaaaaa php5!_zend_mm_free_int+0x2ae
[c:\php-sdk\php55\vc11\x86\php-5.5.13\zend\zend_alloc.c @ 2110]
01bd84b0 01000000 0xaaaaaaaa
01bd84b4 aaaaaaaa iconv+0x20000
01bd84b8 aaaaaaaa 0xaaaaaaaa
01bd84bc 00000000 0xaaaaaaaa
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=68396&edit=1