#23811 [NEW]: Global Varible Over Write
| From: | LouisGreen at pljg dot freeserve dot co dot uk <LouisGr | Date: | Mon, 26 May 2003 11:52:26 +0000 |
| Subject: | #23811 [NEW]: Global Varible Over Write | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-40440@lists.php.net to get a copy of this message | ||
From: LouisGreen at pljg dot freeserve dot co dot uk <LouisGr
Operating system: Windows XP
PHP version: 4.3.1
PHP Bug Type: Variables related
Bug description: Global Varible Over Write
It seems that when you wish to export a varible, you can do it as return
$varible, return an array(), or globalise it. If you return something,
information for that varible can only travel one way when the script is
running, and that is out of the function.
function fn() {
$varible = "something";
return $variable;
}
echo fn();
OR
$newvariable = fn();
Although if global was used, it creates a pointer to a varible, whether it
existed or not, and makes whatever is globalised in the function linked to
that global pointer. So if the pointer was global $varible, and then you
set a value to $varible, it would then be accessible in the global scope.
But what if later on in the script that global was redefine? This means
that whatever is put into the global array, the information that is set in
the pointer, can be set at any point (overiden). Here is an example that
might make this a little clearer:
function fn1() {
global $varible; // Pointer to the global array
$varible = "something";
}
fn1();
echo $varible; // Prints something
$varible = "12345";
echo $varible; // Prints 12345
function fn2() {
global $varible; // Pointer to the global array
echo $varible;
}
fn2(); // echos $varible which contains "12345"
Basically with the global array, it can be set to refer to something
already defined or set it to something, (a pointer) such as varible you
plan to create in the function, and later possibly over ride the pointer
with something else.
---------------------------------------------
This was originally posted in the manual, but was removed. I was notified
of this via email, which suggested I do a bug report, or report it as a
security flaw. I'm not sure which is best, so I entered in a bug report.
--
Edit bug report at http://bugs.php.net/?id=23811&edit=1
--
Try a CVS snapshot: http://bugs.php.net/fix.php?id=23811&r=trysnapshot
Fixed in CVS: http://bugs.php.net/fix.php?id=23811&r=fixedcvs
Fixed in release: http://bugs.php.net/fix.php?id=23811&r=alreadyfixed
Need backtrace: http://bugs.php.net/fix.php?id=23811&r=needtrace
Try newer version: http://bugs.php.net/fix.php?id=23811&r=oldversion
Not developer issue: http://bugs.php.net/fix.php?id=23811&r=support
Expected behavior: http://bugs.php.net/fix.php?id=23811&r=notwrong
Not enough info: http://bugs.php.net/fix.php?id=23811&r=notenoughinfo
Submitted twice: http://bugs.php.net/fix.php?id=23811&r=submittedtwice
register_globals: http://bugs.php.net/fix.php?id=23811&r=globals
PHP 3 support discontinued: http://bugs.php.net/fix.php?id=23811&r=php3
Daylight Savings: http://bugs.php.net/fix.php?id=23811&r=dst
IIS Stability: http://bugs.php.net/fix.php?id=23811&r=isapi
Install GNU Sed: http://bugs.php.net/fix.php?id=23811&r=gnused