Bug #73087 [Opn]: Memory corruption in bindParam

From: Date: Thu, 15 Sep 2016 15:40:51 +0000
Subject: Bug #73087 [Opn]: Memory corruption in bindParam
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-204069@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73087&edit=1

 ID:                 73087
 User updated by:    dorin dot marcoci at gmail dot com
 Reported by:        dorin dot marcoci at gmail dot com
 Summary:            Memory corruption in bindParam
 Status:             Open
 Type:               Bug
 Package:            PDO Firebird
 Operating System:   Debian 8.5
 PHP Version:        7.0.10
 Block user comment: N
 Private report:     N

 New Comment:

Strange, if I try without utf8_encode I get an error from Firebird Server:
Dynamic SQL Error SQL error code = -303 Malformed string
NAME, CONTENT have UTF8 charset and collate
Content are passed as raw bytes and server check if string is encoded properly.
But, in fact, a pure hex string should be considered valid utf8 string.


Previous Comments:
------------------------------------------------------------------------
[2016-09-15 13:04:42] cmb@php.net

The utf8_encode() is a no-op for hexadecimal strings, so this
doesn't appear to be UTF-8 related. This issue might be related to
bug #61183.

------------------------------------------------------------------------
[2016-09-15 07:58:56] dorin dot marcoci at gmail dot com

Description:
------------
This bug is always reproductive by running script below.
PHP crashes with SIGSEGV and Nginx returns "Bad Gateway".

The problem seems to be in assigning UTF8 encoded string to BLOB param.
Crash happens on second statement, while fetchAll.

ENVIRONEMENT:

  Debian 8.5
  Firebird 2.5.4
  PHP-fpm 7.0.10
  Nginx 1.6.2

TABLE DDL:

SET SQL DIALECT 3;

CREATE TABLE TA_TEST (
    ID       DS_ID NOT NULL /* DS_ID = BIGINT */,
    NAME     DT_CHAR50U NOT NULL /* DT_CHAR50U = VARCHAR(50) */,
    CONTENT  DT_TEXTU NOT NULL /* DT_TEXTU = BLOB SUB_TYPE 1 SEGMENT SIZE 100 */
);

ALTER TABLE TA_TEST ADD CONSTRAINT PK_TA_TEST PRIMARY KEY (ID);

Test script:
---------------
<?php

$C = [
	'kind' => 'firebird',
	'host' => 'localhost',
	'port' => 3050,
	'base' => 'testbase',
	'charset' => 'utf8',
	'user' => 'SYSDBA',
	'password' => 'masterkey',
	'options' => [
		PDO::ATTR_PERSISTENT => TRUE,
		PDO::ATTR_CASE => PDO::CASE_LOWER,
		PDO::ATTR_DEFAULT_FETCH_MODE => PDO::FETCH_ASSOC,
		PDO::ATTR_ERRMODE => PDO::ERRMODE_EXCEPTION
	]

];

$S =
$C['kind'].':host='.$C['host'].';port='.$C['port'].';dbname='.$C['base'].';charset='.$C['charset'];
$D = new PDO($S, $C['user'], $C['password'], $C['options']);

$Q = $D->prepare('insert into ta_test (id, name, content) values (next value for gs_id,
:name, :content)');
for ($I = 0; $I < 100; $I++) {
	$Params = [
		'name' => utf8_encode(bin2hex(random_bytes(20))),
		'content' =>  utf8_encode(bin2hex(random_bytes(20)))
	];
	foreach ($Params as $Param => $Value)
		$Q->bindValue($Param, $Value);
	$Q->execute();
	$R = $Q->fetch();
	echo 'I:'.$I;
	print_r($R);
}

$E = $D->prepare('select first 100 id, name, content from ta_test');
$E->execute();
$T = $E->fetchAll();
print_r($T);

echo 'OK!';

Expected result:
----------------
Run without crashes

Actual result:
--------------
SIGSEGV, Memory corruption.
Please solve this annoying bug, it's a stopper for us.


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=73087&edit=1


Thread (7 messages)

« previous php.bugs (#204069) next »