Bug #77137 [Com]: preg_replace memory exhaustion

From: Date: Sat, 10 Nov 2018 23:38:29 +0000
Subject: Bug #77137 [Com]: preg_replace memory exhaustion
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-217893@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77137&edit=1 ID: 77137 Comment by: spam2 at rhsoft dot net Reported by: php at abiusx dot com Summary: preg_replace memory exhaustion Status: Open Type: Bug Package: *Regular Expressions Operating System: macOS Mojave PHP Version: 7.2.12 Block user comment: N Private report: N New Comment: > or explain that pattern/replacement should not come from user input breaking news: until you prove the opposite user inout is always bad Previous Comments: ------------------------------------------------------------------------ [2018-11-10 23:31:05] php at abiusx dot com Description: ------------ The following code will result in memory exhaustion and very long execution times: preg_replace(array_fill(0, 10, '/()/'),str_repeat("&", 10),NULL); https://3v4l.org/LnV37 Either add an example to the docs, or explain that pattern/replacement should not come from user input. Test script: --------------- <?php preg_replace(array_fill(0, 10, '/()/'),str_repeat("&", 10),NULL); ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=77137&edit=1

« previous php.bugs (#217893) next »