Bug #73087 [Opn->Csd]: Memory corruption in bindParam

From: Date: Sun, 06 Nov 2016 16:15:38 +0000
Subject: Bug #73087 [Opn->Csd]: Memory corruption in bindParam
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-205202@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73087&edit=1

 ID:                 73087
 Updated by:         ab@php.net
 Reported by:        dorin dot marcoci at gmail dot com
 Summary:            Memory corruption in bindParam
-Status:             Open
+Status:             Closed
 Type:               Bug
 Package:            PDO Firebird
 Operating System:   Debian 8.5
 PHP Version:        7.0.10
-Assigned To:        
+Assigned To:        ab
 Block user comment: N
 Private report:     N

 New Comment:

Fixed with https://github.com/php/php-src/pull/2183/

Thanks.


Previous Comments:
------------------------------------------------------------------------
[2016-09-16 17:23:57] cmb@php.net

I can reproduce the segfault on PHP 7.0 (with and without the
utf8_encode(), and even with string literals). This issue is
actually a duplicate of bug 61183. See there for further info.

However, there are also memory leaks caused by your supplied test
script, namely during executing/fetching the SELECT statement.
Thus I'm leaving this ticket open.

------------------------------------------------------------------------
[2016-09-16 17:23:26] cmb@php.net

Related To: Bug #61183

------------------------------------------------------------------------
[2016-09-15 15:40:50] dorin dot marcoci at gmail dot com

Strange, if I try without utf8_encode I get an error from Firebird Server:
Dynamic SQL Error SQL error code = -303 Malformed string
NAME, CONTENT have UTF8 charset and collate
Content are passed as raw bytes and server check if string is encoded properly.
But, in fact, a pure hex string should be considered valid utf8 string.

------------------------------------------------------------------------
[2016-09-15 13:04:42] cmb@php.net

The utf8_encode() is a no-op for hexadecimal strings, so this
doesn't appear to be UTF-8 related. This issue might be related to
bug #61183.

------------------------------------------------------------------------
[2016-09-15 07:58:56] dorin dot marcoci at gmail dot com

Description:
------------
This bug is always reproductive by running script below.
PHP crashes with SIGSEGV and Nginx returns "Bad Gateway".

The problem seems to be in assigning UTF8 encoded string to BLOB param.
Crash happens on second statement, while fetchAll.

ENVIRONEMENT:

  Debian 8.5
  Firebird 2.5.4
  PHP-fpm 7.0.10
  Nginx 1.6.2

TABLE DDL:

SET SQL DIALECT 3;

CREATE TABLE TA_TEST (
    ID       DS_ID NOT NULL /* DS_ID = BIGINT */,
    NAME     DT_CHAR50U NOT NULL /* DT_CHAR50U = VARCHAR(50) */,
    CONTENT  DT_TEXTU NOT NULL /* DT_TEXTU = BLOB SUB_TYPE 1 SEGMENT SIZE 100 */
);

ALTER TABLE TA_TEST ADD CONSTRAINT PK_TA_TEST PRIMARY KEY (ID);

Test script:
---------------
<?php

$C = [
	'kind' => 'firebird',
	'host' => 'localhost',
	'port' => 3050,
	'base' => 'testbase',
	'charset' => 'utf8',
	'user' => 'SYSDBA',
	'password' => 'masterkey',
	'options' => [
		PDO::ATTR_PERSISTENT => TRUE,
		PDO::ATTR_CASE => PDO::CASE_LOWER,
		PDO::ATTR_DEFAULT_FETCH_MODE => PDO::FETCH_ASSOC,
		PDO::ATTR_ERRMODE => PDO::ERRMODE_EXCEPTION
	]

];

$S =
$C['kind'].':host='.$C['host'].';port='.$C['port'].';dbname='.$C['base'].';charset='.$C['charset'];
$D = new PDO($S, $C['user'], $C['password'], $C['options']);

$Q = $D->prepare('insert into ta_test (id, name, content) values (next value for gs_id,
:name, :content)');
for ($I = 0; $I < 100; $I++) {
	$Params = [
		'name' => utf8_encode(bin2hex(random_bytes(20))),
		'content' =>  utf8_encode(bin2hex(random_bytes(20)))
	];
	foreach ($Params as $Param => $Value)
		$Q->bindValue($Param, $Value);
	$Q->execute();
	$R = $Q->fetch();
	echo 'I:'.$I;
	print_r($R);
}

$E = $D->prepare('select first 100 id, name, content from ta_test');
$E->execute();
$T = $E->fetchAll();
print_r($T);

echo 'OK!';

Expected result:
----------------
Run without crashes

Actual result:
--------------
SIGSEGV, Memory corruption.
Please solve this annoying bug, it's a stopper for us.


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=73087&edit=1


Thread (7 messages)

« previous php.bugs (#205202) next »