PHP 4.0 Bug #8421: preg_split() reproduce crash if (argc == 1)
| From: | sagawa at sohgoh dot net | Date: | Tue, 26 Dec 2000 09:03:11 +0000 |
| Subject: | PHP 4.0 Bug #8421: preg_split() reproduce crash if (argc == 1) | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-42265@lists.php.net to get a copy of this message | ||
From: sagawa@sohgoh.net
Operating system: Linux, Win32, Solaris and other all systems
PHP version: 4.0.4
PHP Bug Type: PCRE related
Bug description: preg_split() reproduce crash if (argc == 1)
When preg_split's argc is only 1, like preg_split("/foo/"),
reproduce crash.
The cause of this problem is to forget the check of argc==1
in ext/pcre/php_pcre.c line 1070.
1068 /* Get function parameters and do error checking */
1069 argc = ZEND_NUM_ARGS();
1070 if (argc < 1 || argc > 4 ||
zend_get_parameters_ex(argc, ®ex, &subject, &limit,
&flags) == FAILURE) {
1071 WRONG_PARAM_COUNT;
1072 }
Thus this should be
1070 if (argc < 2 || argc >4 || ...
This problem reason is very clear, so I don't attach gdb
backtrace. Thank you.
--
Edit Bug report at: http://bugs.php.net/?id=8421&edit=1