#21523 [Ana->Asn]: number_format causes call to emalloc for a negative amount of memory
| From: | wez@php.net | Date: | Thu, 09 Jan 2003 13:20:31 +0000 |
| Subject: | #21523 [Ana->Asn]: number_format causes call to emalloc for a negative amount of memory | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-29568@lists.php.net to get a copy of this message | ||
ID: 21523
Updated by: wez@php.net
Reported By: cteubner@ncw-av.com
-Status: Analyzed
+Status: Assigned
Bug Type: Strings related
Operating System: Windows 2000
PHP Version: 4.3.0
-Assigned To:
+Assigned To: wez
New Comment:
working on a fix
Previous Comments:
------------------------------------------------------------------------
[2003-01-09 06:36:52] wez@php.net
sprintf under win32 can crash when the format width is too large.
Changing the emalloc + sprintf to spprintf highlights a problem in our
spprintf implementation; it only returns a string of 80 chars.
This length causes the reslen calculation to produce a negative number
and thus emalloc to fail.
------------------------------------------------------------------------
[2003-01-09 06:20:14] busia@tiscali.it
I have tried to reproduce this error on windows and linux:
Windows XP professional + php 4.3.0:
bug reproduced
FATAL: emalloc(): Unable to allocate -207 bytes
Linux Redhat 7.0 + php 4.3.0
bug NOT reproduced. the script works well.
only windows systems seems to be affected by the bug
------------------------------------------------------------------------
[2003-01-09 06:15:25] nicos@php.net
Verified under WIN32.
------------------------------------------------------------------------
[2003-01-09 06:05:50] nicos@php.net
I can't reproduce this error under Linux, FreeBSD.
------------------------------------------------------------------------
[2003-01-08 13:05:47] cteubner@ncw-av.com
When the following line is run:
echo number_format(2, 2678);
The following error appears in the Apache error log:
FATAL: emalloc(): Unable to allocate -1112 bytes
-259 and -123 have also appeared.
Clearly I accidentally used number_format in the reverse
direction that I meant to. However, it seems like whatever is
requesting memory for number_format is experiencing integer overflow.
That doesn't seem right.
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=21523&edit=1