Bug #77137 [Com]: preg_replace memory exhaustion
| From: | spam2 at rhsoft dot net | Date: | Sun, 11 Nov 2018 03:32:02 +0000 |
| Subject: | Bug #77137 [Com]: preg_replace memory exhaustion | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-217898@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77137&edit=1
ID: 77137
Comment by: spam2 at rhsoft dot net
Reported by: php at abiusx dot com
Summary: preg_replace memory exhaustion
Status: Not a bug
Type: Bug
Package: *Regular Expressions
Operating System: macOS Mojave
PHP Version: 7.2.12
Block user comment: N
Private report: N
New Comment:
if you would know what you are doing you would have tried preg_replace(array_fill(0, 10,
'/()/'),str_repeat("X", 10),'');
instead you wrote "I was unable to see any reference to & in the docs. I am assuming
it's a backreference and thus the computational complexity is growing exponentially" which
is nonsense
the problem is your pattern and so "or explain that pattern/replacement should not come from
user input" is nonsense too while that the pattern must not come from user input is pretty
clear for everyone
besides that when you do a preg_replace on a empty string or NULL in live code you don't know
what you are doing because the whole code could be wrapped in if(!empty($subject)) to save
ressources from the start
Previous Comments:
------------------------------------------------------------------------
[2018-11-11 00:10:17] requinix@php.net
This isn't a community. This is a bug tracker. There's a certain expectation that people
who submit bug reports have done some investigation into their own suppositions to determine whether
their problem is, in fact, with PHP or whether there is something wrong with their own code.
In this case it was the latter. And it was fairly easy to show that.
------------------------------------------------------------------------
[2018-11-11 00:04:09] php at abiusx dot com
Why is this community so toxic.
1. I know what I am doing.
2. This is not my code.
3. We're running a PHP anti-malware sandbox on a large (20TB) codebase and this is one of the
instances that is crashing the sandbox (unexpected behavior)
That's why it's being shared. If you don't like it, don't look at it.
------------------------------------------------------------------------
[2018-11-10 23:55:27] requinix@php.net
The problem here is you don't know what you're doing.
Here's an exercise:
1. Try your code with a different replacement character than "&".
2. Try with only one /()/ regex and note the final result.
3. Try with two regexes and note the result.
4. Try with three.
------------------------------------------------------------------------
[2018-11-10 23:44:50] php at abiusx dot com
preg_replace and similar functions are regularly use to parse, sanitize and validate user input.
I admit in this case, the pattern also needs to be something very specific, but the replacement
string is the major factor here, which can come from the user in many scenarios.
I was unable to see any reference to "&" in the docs. I am assuming it's a
backreference and thus the computational complexity is growing exponentially, but that'd be a
very good point to make in the docs (or at least in the comments, or for future reference just in
case someone googles it).
------------------------------------------------------------------------
[2018-11-10 23:38:29] spam2 at rhsoft dot net
> or explain that pattern/replacement should not come from user input
breaking news: until you prove the opposite user inout is always bad
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=77137
--
Edit this bug report at https://bugs.php.net/bug.php?id=77137&edit=1