Bug #4783: segfault in page cleanup

From: Date: Fri, 02 Jun 2000 15:38:24 +0000
Subject: Bug #4783: segfault in page cleanup
Groups: php.dev 
Request: Send a blank email to php-dev+get-20063@lists.php.net to get a copy of this message
From: dave.dunkin@vista.com Operating system: RH6.2 PHP version: 3.0.16 PHP Bug Type: Reproduceable crash Bug description: segfault in page cleanup PHP blows up in the function pval_destructor (variables.c) on line 72. It tries to free what it thinks is a string, but it's not null-terminated. This happens consistently on certain pages. Our pages are very complex and we do a lot of requires and includes. I stuck some code in to print out pvalue->value.str.val before it is deleted and it always blows up at the same spot on the page (or rather, as it is freeing the tokens from the page). If I comment out the section of code where it fails, it will crash later, so it appears to happen after a certain number of tokens. I can keep it from segfaulting by checking to see if the string is null-terminated before freeing it, but obviously this is avoiding the problem and results in a memory leak. PHP 3.0.13-16 Apache 1.3.9 Linux 2.2.14 glibc 2.1.3

« previous php.dev (#20063) next »