PHP 4.0 Bug #7509: Problem (buffer overflow?) with ereg()

From: Date: Sat, 28 Oct 2000 10:12:58 +0000
Subject: PHP 4.0 Bug #7509: Problem (buffer overflow?) with ereg()
Groups: php.dev 
Request: Send a blank email to php-dev+get-36221@lists.php.net to get a copy of this message
From: ignacio@openservices.net Operating system: Red Hat Linux 6.2 PHP version: 4.0 Latest CVS (28/10/2000) PHP Bug Type: Regexps related Bug description: Problem (buffer overflow?) with ereg() When I give ereg() a sufficiently complex RE, PHP seems to roll over and die or something the next time it calls ereg(). It has exhibited this behavior since 4.0.1pl2, when we first put the code in place. Here's the code: """ while (ereg("^((.|\n)*)<[[:space:]]*[Ff][Oo][Rr][Mm][Ss][Ee][Tt][[:space:]]*([Tt][Yy][Pp][Ee]=(\"[^\"]*\"|[^\">]*))?[[:space:]]*>((.|\n)*)$", $string, $out)) { error_log("after 1",0); flush(); if ($out[4][0]=="\"") { error_log("after 2",0); flush(); $type=substr($out[4], 1, -1); error_log("after 3",0); flush(); } else { error_log("after 4",0); flush(); $type=$out[4]; error_log("after 5",0); flush(); }; error_log("after 6",0); $string=$out[1].FORMSETFUN($type).$out[5]; error_log("after 7",0); flush(); $formexists=1; }; error_log("after formset",0); flush(); """ It gets to "after 7" and then dies. If the 'while' is changed to an 'if', the problem exhibits itself on subsequent calls to ereg() further down. PHP is configured to use the system RE libs, so I'm wondering if the problem might be in there. Nonetheless, I'm putting it in the PHP bug list so I can be sure. -- Edit Bug report at: http://bugs.php.net/?id=7509&edit=1

« previous php.dev (#36221) next »