Bug #61183 [Asn]: Firebird PDO memory corruption

From: Date: Fri, 16 Sep 2016 17:23:26 +0000
Subject: Bug #61183 [Asn]: Firebird PDO memory corruption
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-204084@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=61183&edit=1 ID: 61183 Updated by: cmb@php.net Reported by: noxwizard at gmail dot com Summary: Firebird PDO memory corruption Status: Assigned Type: Bug Package: PDO Firebird Operating System: Windows Server 2008 x86 PHP Version: 5.5 Assigned To: mariuz Block user comment: N Private report: N New Comment: I can't reproduce this issue with the supplied test script, but the reproducer of bug 73087 also exhibits this bug. James' assessment is basically correct. Firstly, it should be noted that the zval_dtor() is wrong; that should be zval_ptr_dtor(). But that wouldn't solve the issue due to the aliasing of param. The actual problem is indeed the SEPARATE_ZVAL(), which simply can't work there. If the refcount is 1, SEPARATE_ZVAL() is a no-op, and zval_ptr_dtor() would destroy the zval, albeit it is later used elsewhere. The clean solution would be to make a copy of the zval, so the convert_to_string_ex() can savely be applied, and to destroy that copy later. However, it appears to me that there's no need to use a copy at all, and that the convert_to_string_ex() can nonetheless savely be applied (see attached patch firebird_bind_blob). Previous Comments: ------------------------------------------------------------------------ [2016-09-16 17:22:13] cmb@php.net The following patch has been added/updated: Patch Name: firebird_bind_blob Revision: 1474046532 URL: https://bugs.php.net/patch-display.php?bug=61183&patch=firebird_bind_blob&revision=1474046532 ------------------------------------------------------------------------ [2016-09-15 13:04:42] cmb@php.net Related To: Bug #73087 ------------------------------------------------------------------------ [2015-07-16 14:09:00] mariuz@php.net db created https://gist.github.com/mariuz/108810265b9c67fc747d#file-test-db-for-phpbug-61183-sql test https://gist.github.com/mariuz/b00d148812e3a1657ef1 ran without issues ... Statement run: 4999 ------------------------------------------------------------------------ [2015-07-16 13:41:28] mariuz@php.net Started to test the patch patch -p1 < ~/Downloads/Blob_Bind_Fix.patch.txt patching file ext/pdo_firebird/firebird_statement.c Hunk #1 succeeded at 422 (offset -2 lines). ------------------------------------------------------------------------ [2013-02-13 04:25:05] james at kenjim dot com Related To: Bug #63356 ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=61183 -- Edit this bug report at https://bugs.php.net/bug.php?id=61183&edit=1

« previous php.bugs (#204084) next »