Bug #77137 [Com]: preg_replace memory exhaustion

From: Date: Sun, 11 Nov 2018 03:32:02 +0000
Subject: Bug #77137 [Com]: preg_replace memory exhaustion
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-217898@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77137&edit=1 ID: 77137 Comment by: spam2 at rhsoft dot net Reported by: php at abiusx dot com Summary: preg_replace memory exhaustion Status: Not a bug Type: Bug Package: *Regular Expressions Operating System: macOS Mojave PHP Version: 7.2.12 Block user comment: N Private report: N New Comment: if you would know what you are doing you would have tried preg_replace(array_fill(0, 10, '/()/'),str_repeat("X", 10),''); instead you wrote "I was unable to see any reference to & in the docs. I am assuming it's a backreference and thus the computational complexity is growing exponentially" which is nonsense the problem is your pattern and so "or explain that pattern/replacement should not come from user input" is nonsense too while that the pattern must not come from user input is pretty clear for everyone besides that when you do a preg_replace on a empty string or NULL in live code you don't know what you are doing because the whole code could be wrapped in if(!empty($subject)) to save ressources from the start Previous Comments: ------------------------------------------------------------------------ [2018-11-11 00:10:17] requinix@php.net This isn't a community. This is a bug tracker. There's a certain expectation that people who submit bug reports have done some investigation into their own suppositions to determine whether their problem is, in fact, with PHP or whether there is something wrong with their own code. In this case it was the latter. And it was fairly easy to show that. ------------------------------------------------------------------------ [2018-11-11 00:04:09] php at abiusx dot com Why is this community so toxic. 1. I know what I am doing. 2. This is not my code. 3. We're running a PHP anti-malware sandbox on a large (20TB) codebase and this is one of the instances that is crashing the sandbox (unexpected behavior) That's why it's being shared. If you don't like it, don't look at it. ------------------------------------------------------------------------ [2018-11-10 23:55:27] requinix@php.net The problem here is you don't know what you're doing. Here's an exercise: 1. Try your code with a different replacement character than "&". 2. Try with only one /()/ regex and note the final result. 3. Try with two regexes and note the result. 4. Try with three. ------------------------------------------------------------------------ [2018-11-10 23:44:50] php at abiusx dot com preg_replace and similar functions are regularly use to parse, sanitize and validate user input. I admit in this case, the pattern also needs to be something very specific, but the replacement string is the major factor here, which can come from the user in many scenarios. I was unable to see any reference to "&" in the docs. I am assuming it's a backreference and thus the computational complexity is growing exponentially, but that'd be a very good point to make in the docs (or at least in the comments, or for future reference just in case someone googles it). ------------------------------------------------------------------------ [2018-11-10 23:38:29] spam2 at rhsoft dot net > or explain that pattern/replacement should not come from user input breaking news: until you prove the opposite user inout is always bad ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=77137 -- Edit this bug report at https://bugs.php.net/bug.php?id=77137&edit=1

« previous php.bugs (#217898) next »