Bug #73087 [NEW]: Memory corruption in bindParam / utf8

From: Date: Thu, 15 Sep 2016 07:58:57 +0000
Subject: Bug #73087 [NEW]: Memory corruption in bindParam / utf8
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-204054@lists.php.net to get a copy of this message
From:             dorin dot marcoci at gmail dot com
Operating system: Debian 8.5
PHP version:      7.0.10
Package:          PDO Firebird
Bug Type:         Bug
Bug description:Memory corruption in bindParam / utf8

Description:
------------
This bug is always reproductive by running script below.
PHP crashes with SIGSEGV and Nginx returns "Bad Gateway".

The problem seems to be in assigning UTF8 encoded string to BLOB param.
Crash happens on second statement, while fetchAll.

ENVIRONEMENT:

  Debian 8.5
  Firebird 2.5.4
  PHP-fpm 7.0.10
  Nginx 1.6.2

TABLE DDL:

SET SQL DIALECT 3;

CREATE TABLE TA_TEST (
    ID       DS_ID NOT NULL /* DS_ID = BIGINT */,
    NAME     DT_CHAR50U NOT NULL /* DT_CHAR50U = VARCHAR(50) */,
    CONTENT  DT_TEXTU NOT NULL /* DT_TEXTU = BLOB SUB_TYPE 1 SEGMENT
SIZE 100 */
);

ALTER TABLE TA_TEST ADD CONSTRAINT PK_TA_TEST PRIMARY KEY (ID);

Test script:
---------------
<?php

$C = [
	'kind' => 'firebird',
	'host' => 'localhost',
	'port' => 3050,
	'base' => 'testbase',
	'charset' => 'utf8',
	'user' => 'SYSDBA',
	'password' => 'masterkey',
	'options' => [
		PDO::ATTR_PERSISTENT => TRUE,
		PDO::ATTR_CASE => PDO::CASE_LOWER,
		PDO::ATTR_DEFAULT_FETCH_MODE => PDO::FETCH_ASSOC,
		PDO::ATTR_ERRMODE => PDO::ERRMODE_EXCEPTION
	]

];

$S =
$C['kind'].':host='.$C['host'].';port='.$C['port'].';dbname='.$C['base'].';charset='.$C['charset'];
$D = new PDO($S, $C['user'], $C['password'], $C['options']);

$Q = $D->prepare('insert into ta_test (id, name, content) values (next
value for gs_id, :name, :content)');
for ($I = 0; $I < 100; $I++) {
	$Params = [
		'name' => utf8_encode(bin2hex(random_bytes(20))),
		'content' =>  utf8_encode(bin2hex(random_bytes(20)))
	];
	foreach ($Params as $Param => $Value)
		$Q->bindValue($Param, $Value);
	$Q->execute();
	$R = $Q->fetch();
	echo 'I:'.$I;
	print_r($R);
}

$E = $D->prepare('select first 100 id, name, content from ta_test');
$E->execute();
$T = $E->fetchAll();
print_r($T);

echo 'OK!';

Expected result:
----------------
Run without crashes

Actual result:
--------------
SIGSEGV, Memory corruption.
Please solve this annoying bug, it's a stopper for us.

-- 
Edit bug report at https://bugs.php.net/bug.php?id=73087&edit=1
-- 
Try a snapshot (PHP 5.4):   https://bugs.php.net/fix.php?id=73087&r=trysnapshot54
Try a snapshot (PHP 5.5):   https://bugs.php.net/fix.php?id=73087&r=trysnapshot55
Try a snapshot (trunk):     https://bugs.php.net/fix.php?id=73087&r=trysnapshottrunk
Fixed in SVN:               https://bugs.php.net/fix.php?id=73087&r=fixed
Fixed in release:           https://bugs.php.net/fix.php?id=73087&r=alreadyfixed
Need backtrace:             https://bugs.php.net/fix.php?id=73087&r=needtrace
Need Reproduce Script:      https://bugs.php.net/fix.php?id=73087&r=needscript
Try newer version:          https://bugs.php.net/fix.php?id=73087&r=oldversion
Not developer issue:        https://bugs.php.net/fix.php?id=73087&r=support
Expected behavior:          https://bugs.php.net/fix.php?id=73087&r=notwrong
Not enough info:            https://bugs.php.net/fix.php?id=73087&r=notenoughinfo
Submitted twice:            https://bugs.php.net/fix.php?id=73087&r=submittedtwice
register_globals:           https://bugs.php.net/fix.php?id=73087&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=73087&r=php4
Daylight Savings:           https://bugs.php.net/fix.php?id=73087&r=dst
IIS Stability:              https://bugs.php.net/fix.php?id=73087&r=isapi
Install GNU Sed:            https://bugs.php.net/fix.php?id=73087&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=73087&r=float
No Zend Extensions:         https://bugs.php.net/fix.php?id=73087&r=nozend
MySQL Configuration Error:  https://bugs.php.net/fix.php?id=73087&r=mysqlcfg



Thread (7 messages)

« previous php.bugs (#204054) next »