php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #18422 emalloc() call crashes Apache (backtrace provided)
Submitted: 2002-07-18 16:24 UTC Modified: 2002-09-11 11:43 UTC
From: acs at hourglassone dot com Assigned:
Status: Closed Package: Reproducible crash
PHP Version: 4.2.1 OS: Redhat Linux 7.2
Private report: No CVE-ID: None
 [2002-07-18 16:24 UTC] acs at hourglassone dot com
I have a script that proxies a request through Curl to an instance of apache running on the same machine with a different port number.  This script worked great until I installed 4.2.1.

Error logs show:
FATAL: emalloc():  Unable to allocate -491 bytes

I'm not entirely sure where the error is being caused. The script in question is using curl, xpath, and mysql.  

Running HTTPD with -X under gdb yields this backtrace:

#0  0x4010da01 in __kill () from /lib/i686/libc.so.6
#1  0x404a9a51 in _emalloc (size=4294966827, __zend_filename=0x405aaa60 "zend_API.c", __zend_lineno=845, __zend_orig_filename=0x0,
    __zend_orig_lineno=0) at zend_alloc.c:173
#2  0x404aa17d in _estrndup (s=0x814a3a3 "", length=4294966826, __zend_filename=0x405aaa60 "zend_API.c", __zend_lineno=845,
    __zend_orig_filename=0x0, __zend_orig_lineno=0) at zend_alloc.c:340
#3  0x404c949a in add_next_index_stringl (arg=0x814bde4, str=0x814a3a3 "", length=4294966826, duplicate=1) at zend_API.c:845
#4  0x40555489 in php_split (ht=2, return_value=0x814bde4, this_ptr=0x0, return_value_used=1, icase=0) at reg.c:594
#5  0x405554b0 in zif_split (ht=2, return_value=0x814bde4, this_ptr=0x0, return_value_used=1) at reg.c:604
#6  0x404b6455 in execute (op_array=0x812ac8c) at ./zend_execute.c:1598
#7  0x404b6667 in execute (op_array=0x8134b94) at ./zend_execute.c:1638
#8  0x404b6667 in execute (op_array=0x8138674) at ./zend_execute.c:1638
#9  0x404b6667 in execute (op_array=0x8121de4) at ./zend_execute.c:1638
#10 0x404c70a8 in zend_execute_scripts (type=8, retval=0x0, file_count=3) at zend.c:810
#11 0x404d98ca in php_execute_script (primary_file=0xbffff5b0) at main.c:1381
#12 0x404d4316 in apache_php_module_main (r=0x8115cec, display_source_mode=0) at sapi_apache.c:90
#13 0x404d5184 in send_php (r=0x8115cec, display_source_mode=0, filename=0x81179e4 "/www/redir.php") at mod_php4.c:575
#14 0x404d51f1 in send_parsed_php (r=0x8115cec) at mod_php4.c:590
#15 0x08054757 in ap_invoke_handler ()
#16 0x080695af in process_request_internal ()
#17 0x08069610 in ap_process_request ()
#18 0x08060799 in child_main ()
#19 0x08060968 in make_child ()
#20 0x08060adc in startup_children ()
#21 0x08061154 in standalone_main ()
#22 0x080619c3 in main ()
#23 0x400fb507 in __libc_start_main (main=0x8061610 <main>, argc=3, ubp_av=0xbffff9e4, init=0x804ebd4 <_init>, fini=0x8080c40 <_fini>,
    rtld_fini=0x4000dc14 <_dl_fini>, stack_end=0xbffff9dc) at ../sysdeps/generic/libc-start.c:129

Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2002-07-18 16:31 UTC] derick@php.net
It crashes on a split function, can you try to shorten your script to narrow the search for us?

Derick
 [2002-07-18 17:06 UTC] acs at hourglassone dot com
Looks like you're correct..  I added a trim() around the second paramater of split() and it seems to take care of it.  

It would seem that there's no checking done on the size parameter in php_split before calling add_next_index_stringl for the last value.

line number is ext/standard/reg.c:574 in php4.2.2dev

Snippet of code (offending line marked by >>>> <<<<), $sHeader is returned by curl_exec):
class HeaderObj {
	function HeaderObj($sHeader) {
		$this->header = $sHeader;
		$aHeaders = Array();
>>>>
		$aLines = split("\n",$sHeader);
<<<<

		foreach($aLines as $sLine) {
			$temp = split(":",trim($sLine));
			$aHeaders[$temp[0]] = (isset($temp[1])) ? trim($temp[1]) : "";
			if ($temp[0] == "Content-Type") {
				if (!isset($temp[1])) {
					$aHeaders[$temp[0]] = trim("text/html");
				}
			}
		} 
		if (!isset($aHeaders['Content-Type'])) {
			$aHeaders['Content-Type'] = "text/html";
		}
		$this->headers = $aHeaders;
		$this->headers['string'] = $sHeader;
		reset($this->headers);
	}
}

--- 

If I put it in a trim(), with --enable-debug, I get this warning:

<b>Warning</b>:  String is not zero-terminated (HTTP/1.1 200 OK
Date: Thu, 18 Jul 2002 20:58:13 GMT
Server: Apache/1.3.23 (Unix)
Last-Modified: Fri, 28 Jun 2002 23:00:30 GMT
ETag: "736-3d1cea8e"
Accept-Ranges: bytes
Content-Length: 1846
Content-Type: application/x-javascript

Toolbar=search; siteinfopopup=siteinfo; relatedlinkspopup=relatedlinks; twym=webyoumade; searchMethod=Yahoo; twym_disabled=false; ALXSID=ccd89a2e038361a7cb25c7f27130ed86; twym65=D4ABCAC7DEF19AA7979F60CED1A3%2521D7AED1C9EBED9CA59DA7A6DE9099A2E7%2521DB6C8FD3EBE1%2521C5ACD5C5E5DBAF9CA7AB9399C4A5ABA8A89D%2521D1B2D4D5E5A89CA2A1; aid=iKy4Z0eeh000NE
Host: client.alexa.com:2222
Pragma: no-cache
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, */*
Referer: http://client.alexa.com/speed_test/index.html
Accept-Language: en-us

@) (source: zend_execute_API.c:274) in <b>Unknown</b> on line <b>0</b><br />
 [2002-07-18 17:52 UTC] sniper@php.net
Firs try this snapshot:

http://snaps.php.net/php4-latest.tar.gz

And if it does not work, give a short, complete and standalone script which can easily be used to reproduce this. As it seems the crash happens in split(), come up with such script that does NOT include anything but it and the data that crashes it.



 [2002-07-18 18:52 UTC] acs at hourglassone dot com
More info:  I managed to solve the problem by applying the following:

593,595c593,595
<
<       add_next_index_stringl(return_value, strp, size, 1);
<
---
>       if (size > 0) {
>               add_next_index_stringl(return_value, strp, size, 1);
>       }

Don't know if this is a good solution or not.  I will try the latest snapshot tomorrow and see if the problem is solved.

Cheers.
 [2002-07-18 19:25 UTC] sniper@php.net
If it's not fixed in the snapshot (might not be) please
provide us the patch against it (diff -u) and add it here..

 [2002-09-11 11:43 UTC] sniper@php.net
No feedback..should be fixed in 4.2.3 though.

 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Tue Oct 06 13:00:01 2026 UTC