Bug #77137 [Com]: preg_replace memory exhaustion
| From: | spam2 at rhsoft dot net | Date: | Sat, 10 Nov 2018 23:38:29 +0000 |
| Subject: | Bug #77137 [Com]: preg_replace memory exhaustion | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-217893@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77137&edit=1
ID: 77137
Comment by: spam2 at rhsoft dot net
Reported by: php at abiusx dot com
Summary: preg_replace memory exhaustion
Status: Open
Type: Bug
Package: *Regular Expressions
Operating System: macOS Mojave
PHP Version: 7.2.12
Block user comment: N
Private report: N
New Comment:
> or explain that pattern/replacement should not come from user input
breaking news: until you prove the opposite user inout is always bad
Previous Comments:
------------------------------------------------------------------------
[2018-11-10 23:31:05] php at abiusx dot com
Description:
------------
The following code will result in memory exhaustion and very long execution times:
preg_replace(array_fill(0, 10, '/()/'),str_repeat("&", 10),NULL);
https://3v4l.org/LnV37
Either add an example to the docs, or explain that pattern/replacement should not come from user
input.
Test script:
---------------
<?php
preg_replace(array_fill(0, 10, '/()/'),str_repeat("&", 10),NULL);
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=77137&edit=1