Bug #4783: segfault in page cleanup
| From: | dave dot dunkin at vista dot com | Date: | Fri, 02 Jun 2000 15:38:24 +0000 |
| Subject: | Bug #4783: segfault in page cleanup | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-20063@lists.php.net to get a copy of this message | ||
From: dave.dunkin@vista.com
Operating system: RH6.2
PHP version: 3.0.16
PHP Bug Type: Reproduceable crash
Bug description: segfault in page cleanup
PHP blows up in the function pval_destructor (variables.c) on line 72. It tries to free what it
thinks is a string, but it's not null-terminated. This happens consistently on certain pages.
Our pages are very complex and we do a lot of requires and includes. I stuck some code in to print
out pvalue->value.str.val before it is deleted and it always blows up at the same spot on the
page (or rather, as it is freeing the tokens from the page). If I comment out the section of code
where it fails, it will crash later, so it appears to happen after a certain number of tokens. I can
keep it from segfaulting by checking to see if the string is null-terminated before freeing it, but
obviously this is avoiding the problem and results in a memory leak.
PHP 3.0.13-16
Apache 1.3.9
Linux 2.2.14
glibc 2.1.3