Bug #66076 [Opn->Fbk]: Segfault on SimpleXML toString

From: Date: Tue, 24 Oct 2017 14:12:18 +0000
Subject: Bug #66076 [Opn->Fbk]: Segfault on SimpleXML toString
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-212279@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=66076&edit=1

 ID:                 66076
 Updated by:         yunosh@php.net
 Reported by:        mengpg2 at engene dot se
 Summary:            Segfault on SimpleXML toString
-Status:             Open
+Status:             Feedback
 Type:               Bug
 Package:            Reproducible crash
 Operating System:   Linux and MacOS
 PHP Version:        5.4.21
 Block user comment: N
 Private report:     N

 New Comment:

Thank you for taking the time to report a problem with PHP.
Unfortunately you are not using a current version of PHP -- 
the problem might already be fixed. Please download a new
PHP version from http://www.php.net/downloads.php

If you are able to reproduce the bug with one of the latest
versions of PHP, please change the PHP version on this bug report
to the version you tested and change the status back to "Open".
Again, thank you for your continued support of PHP.




Previous Comments:
------------------------------------------------------------------------
[2014-12-30 11:15:50] mengpg2 at engene dot se

I am hand patching zend.c for each version I upgrade or else I experience php code crashing the
Apache instance. I did add feedback, but it was ignored.

------------------------------------------------------------------------
[2014-12-30 10:42:08] php-bugs at lists dot php dot net

No feedback was provided. The bug is being suspended because
we assume that you are no longer experiencing the problem.
If this is not the case and you are able to provide the
information that was requested earlier, please do so and
change the status of the bug back to "Re-Opened". Thank you.

------------------------------------------------------------------------
[2013-11-11 10:13:57] mengpg2 at engene dot se

this is part of the object that crashes in the example.


  ["body"]=>
  object(CFSimpleXML)#12 (2) {
    ["ConsumedCapacityUnits"]=>
    string(3) "0.5"
    ["Item"]=>
    object(CFSimpleXML)#10 (2) {
      ["exif_json"]=>
      object(CFSimpleXML)#15 (1) {
        ["S"]=>
        string(1923) "{"major brand": "Apple QuickTime (.MOV/QT)",
"source image height": "480", "selection time": "0 s",
"gen flags": "0 0 0", "file size": "46 MB", "track
header version": "0", "movie header version": "0",
"compatible brands": "qt", "file permissions": "rw-r--r--",
"duration": "13.35 s", "handler description": "Apple Alias Data
Handler", "source image width": "720", "selection duration":
"0 s", "modify date": "2005:07:25 17:57:00", "minor
version": "2005.3.0", "image height": "480", "current
time": "0 s", "track modify date": "2005:07:25 17:57:00",
"track volume": "0.00%", "compressor id": "dvc", "movie
data size": "4", "y resolution": "72", "image width":
"720", "create date": "2005:07:25 17:56:52", "video frame
rate": "29.97", "track layer": "0", "poster time":
"0 s", "vendor id": "Apple", "graphics mode":
"ditherCopy", "preview time": "0 s", "media modify date":
"2005:07:25 17:57:00", "matrix structure": "1 0 0 0 1 0 0 0 1",
"op color": "32768 32768 3276!
 8", "time scale": "2997", "track duration": "13.35 s",
"avg bitrate": "2 bps", "handler class": "Data Handler",
"gen graphics mode": "ditherCopy", "gen op color": "32768 32768
32768", "file type": "MOV", "exiftool version number":
"8.76", "directory": "/tmp", "media duration": "13.35
s", "preferred volume": "100.00%", "handler vendor id":
"Apple", "image size": "720x480", "track id": "1",
"rotation": "0", "bit depth": "24", "media create
date": "2005:07:25 17:57:00", "gen media version": "0",
"mime type": "video/quicktime", "x resolution": "72",
"compressor name": "DV/DVCPRO - NTSC", "file name":
"672ea710dc1d43a8e951dd6509e42e88_probe.mov", "other format": "tmcd",
"gen balance": "0", "media time scale": "2997", "track
create date": "2005:07:25 17:56:52", "file modification date/time":
"2010:01:29 21:46:02+00:00", "media header version": "0", "next
track id": "3", "handler type": "Alias Data", "preferred
rate": "1", "preview duration": "0 s"}"
      }
      ["pond_item_common"]=>
      object(CFSimpleXML)#14 (1) {
        ["N"]=>
        string(2) "13"
      }
    }
  }
  ["status"]=>
  int(200)
}

------------------------------------------------------------------------
[2013-11-11 09:45:32] mengpg2 at engene dot se

$DDB = new AmazonDynamoDB();
    $DDB->use_ssl = false;
    $Key = array('HashKeyElement' => array(AmazonDynamoDB::TYPE_NUMBER =>
(string)$itemid));
    $Res = $DDB->get_item(array('TableName' => 'pond_item_meta',
'Key' => $Key));
    $tt = (string)$Res->body->Item->exif_json->S;

But this is the offending code. Casting on a CFSimpleXML object. Worked flawlessly to 5.4.7. Is it a
CFSimpleXML bug?

------------------------------------------------------------------------
[2013-11-11 09:33:11] laruence@php.net

seems it's a recursively call to __toString..

like:

<?php

class A {
    public function __toString() {
        return (string)$this;
    }
}


so I think this should not considered as a bug... but a wrong usage

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=66076


--
Edit this bug report at https://bugs.php.net/bug.php?id=66076&edit=1


Thread (12 messages)

« previous php.bugs (#212279) next »