PHP 4.0 Bug #7509: Problem (buffer overflow?) with ereg()
| From: | ignacio at openservices dot net | Date: | Sat, 28 Oct 2000 10:12:58 +0000 |
| Subject: | PHP 4.0 Bug #7509: Problem (buffer overflow?) with ereg() | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-36221@lists.php.net to get a copy of this message | ||
From: ignacio@openservices.net
Operating system: Red Hat Linux 6.2
PHP version: 4.0 Latest CVS (28/10/2000)
PHP Bug Type: Regexps related
Bug description: Problem (buffer overflow?) with ereg()
When I give ereg() a sufficiently complex RE, PHP seems to roll over and die or something the next
time it calls ereg(). It has exhibited this behavior since 4.0.1pl2, when we first put the code in
place.
Here's the code:
"""
while
(ereg("^((.|\n)*)<[[:space:]]*[Ff][Oo][Rr][Mm][Ss][Ee][Tt][[:space:]]*([Tt][Yy][Pp][Ee]=(\"[^\"]*\"|[^\">]*))?[[:space:]]*>((.|\n)*)$",
$string, $out))
{
error_log("after 1",0);
flush();
if ($out[4][0]=="\"")
{
error_log("after 2",0);
flush();
$type=substr($out[4], 1, -1);
error_log("after 3",0);
flush();
}
else
{
error_log("after 4",0);
flush();
$type=$out[4];
error_log("after 5",0);
flush();
};
error_log("after 6",0);
$string=$out[1].FORMSETFUN($type).$out[5];
error_log("after 7",0);
flush();
$formexists=1;
};
error_log("after formset",0);
flush();
"""
It gets to "after 7" and then dies. If the 'while' is changed to an
'if', the problem exhibits itself on subsequent calls to ereg() further down.
PHP is configured to use the system RE libs, so I'm wondering if the problem might be in there.
Nonetheless, I'm putting it in the PHP bug list so I can be sure.
--
Edit Bug report at: http://bugs.php.net/?id=7509&edit=1