php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #17764 crash in ereg_replace (with patch to fix it ;-)
Submitted: 2002-06-14 10:39 UTC Modified: 2002-06-17 11:13 UTC
From: oliver at billix dot franken dot de Assigned:
Status: Closed Package: Reproducible crash
PHP Version: 4.2.1 OS: Linux 2.2.19
Private report: No CVE-ID: None
View Developer Edit
Welcome! If you don't have a Git account, you can't do anything here.
If you reported this bug, you can edit this bug over here.
(description)
Block user comment
Status: Assign to:
Package:
Bug Type:
Summary:
From: oliver at billix dot franken dot de
New email:
PHP Version: OS:

 

 [2002-06-14 10:39 UTC] oliver at billix dot franken dot de
I wanted to replace any umlauts with strings (not chars in octal...) like "\200". I used ereg_replace for this and it worked until PHP 4.2.0 was released. Than php just crashed. I now know there are better solutions to accomplish this, e.g. str_replace... But on the other hand, php shouldn't crash on user input...

Here is the code:

<?php
  $x = "a?b?c";
  $x = ereg_replace ( "?" , "\\200" , $x );
  print "$x\n";
  $x = ereg_replace ( "?" , "\\234" , $x );
  print "$x\n";
?>

The problem is, \\2 is taken as an index into an array, which has only one element. The fix is easy, just check the digit if it is a valid index:

--- reg.c       Sun May  5 10:39:57 2002
+++ reg.c.new   Fri Jun 14 16:13:38 2002
@@ -341,6 +341,7 @@
                        while (*walk)
                                if ('\\' == *walk
                                        && '0' <= walk[1] && '9' >= walk[1]
+                                       && walk[1] - '0' <= re.re_nsub
                                        && subs[walk[1] - '0'].rm_so > -1
                                        && subs[walk[1] - '0'].rm_eo > -1) {
                                        new_l += subs[walk[1] - '0'].rm_eo
@@ -368,6 +369,7 @@
                        while (*walk)
                                if ('\\' == *walk
                                        && '0' <= walk[1] && '9' >= walk[1]
+                                       && walk[1] - '0' <= re.re_nsub
                                        && subs[walk[1] - '0'].rm_so > -1
                                        && subs[walk[1] - '0'].rm_eo > -1
                                        /* this next case shouldn't happen. it does. */

Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2002-06-17 11:13 UTC] andrei@php.net
This bug has been fixed in CVS. You can grab a snapshot of the
CVS version at http://snaps.php.net/. In case this was a documentation 
problem, the fix will show up soon at http://www.php.net/manual/.
In case this was a PHP.net website problem, the change will show
up on the PHP.net site and on the mirror sites.
Thank you for the report, and for helping us make PHP better.


 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Wed Oct 07 20:00:02 2026 UTC