#27678 [Asn->Csd]: number_format() crashes with large numbers.
ID: 27678
Updated by: helly@php.net
Reported By: morten_odegaard at broadpark dot no
-Status: Assigned
+Status: Closed
Bug Type: Math related
Operating System: *
-PHP Version: 5CVS, 4CVS (2005-12-22) (cvs)
+PHP Version: 5CVS, 4CVS (2005-12-26) (cvs)
Assigned To: helly
New Comment:
This bug has been fixed in CVS.
Snapshots of the sources are packaged every three hours; this change
will be in the next snapshot. You can grab the snapshot at
http://snaps.php.net/.
Thank you for the report, and for helping us make PHP better.
Previous Comments:
------------------------------------------------------------------------
[2005-12-25 17:27:01] sniper@php.net
Marcus: It's after Christmas and before New Year's eve!
Fix this.
------------------------------------------------------------------------
[2005-12-21 23:33:06] sniper@php.net
3rd reminder for Marcus: Check this out after Christmas 2005 but before
New Year's eve 2005-2006 :)
------------------------------------------------------------------------
[2005-11-01 11:31:35] sniper@php.net
Marcus, can you check this out please?
------------------------------------------------------------------------
[2005-03-30 10:58:49] kameshj at fastmail dot fm
Regarding the segfault,
In main/snprintf.c:ap_php_cvt has a call to memmove(&buf[mvl], &buf[0],
NDIG-mvl-1); NDIG-mvl-1 becomes -1 in the mentioned defect of double
being 1e80, decimals 3, dec_sep '' and thousand_sep ' '.
As I could see php recognizes a float as hight as 1e308, I feel NDIG
should be set accordingly to higher value let us say 310 or 311.
------------------------------------------------------------------------
[2004-12-12 23:52:48] sniper@php.net
(gdb) run -r "echo number_format(1e80, 3, '', ' ');"
Starting program: /www/php-modules/bin/php -r "echo number_format(1e80,
3, '', ' ');"
[New Thread 1087948032 (LWP 31942)]
Program received signal SIGSEGV, Segmentation fault.
[Switching to Thread 1087948032 (LWP 31942)]
0x4207c0ad in memmove () from /lib/tls/libc.so.6
(gdb) bt
#0 0x4207c0ad in memmove () from /lib/tls/libc.so.6
#1 0xbfffd8e8 in ?? ()
#2 0x08259347 in ap_php_cvt (arg=Cannot access memory at address
0xffffffef
) at /usr/src/web/php/php4/main/snprintf.c:294
Cannot access memory at address 0xffffffff
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
http://bugs.php.net/27678
--
Edit this bug report at http://bugs.php.net/?id=27678&edit=1
Thread (10 messages)