#28974 [Opn->Csd]: array_slice treats large lengths incorrectly
| From: | andrey@php.net | Date: | Sun, 11 Jul 2004 21:32:47 +0000 |
| Subject: | #28974 [Opn->Csd]: array_slice treats large lengths incorrectly | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-62069@lists.php.net to get a copy of this message | ||
ID: 28974
Updated by: andrey@php.net
Reported By: tomas_matousek at hotmail dot com
-Status: Open
+Status: Closed
Bug Type: Arrays related
Operating System: WinXP
PHP Version: 5.0.0RC3
New Comment:
This bug has been fixed in CVS.
Snapshots of the sources are packaged every three hours; this change
will be in the next snapshot. You can grab the snapshot at
http://snaps.php.net/.
Thank you for the report, and for helping us make PHP better.
The same kind of overflow appeared and was fixed in array_splice(),
substr(), substr_replace(), strspn() and strcspn(). Fixed in 4.3.x and
5.0.0-dev
Previous Comments:
------------------------------------------------------------------------
[2004-06-30 16:59:30] tomas_matousek at hotmail dot com
Description:
------------
If offset + length > MAX_INTEGER then array_slice function returns
wrong results (obviously overflows soume integer in its
implementation).
Reproduce code:
---------------
$a = array(0,1,2,3,4,5);
// this is ok:
print_r(array_slice($a,2,2147483645));
// this is wrong:
print_r(array_slice($a,2,2147483646));
Expected result:
----------------
Array
(
[0] => 2
[1] => 3
[2] => 4
[3] => 5
)
Array
(
[0] => 2
[1] => 3
[2] => 4
[3] => 5
)
Actual result:
--------------
Array
(
[0] => 2
[1] => 3
[2] => 4
[3] => 5
)
Array
(
)
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=28974&edit=1