php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #18814 Segfault variable swap
Submitted: 2002-08-08 15:35 UTC Modified: 2002-08-08 16:46 UTC
From: andersena at netscape dot net Assigned:
Status: Not a bug Package: Scripting Engine problem
PHP Version: 4.2.2 OS: Linux 2.4.18 (Mandrake 8.1)
Private report: No CVE-ID: None
Welcome back! If you're the original bug submitter, here's where you can edit the bug or add additional notes.
If you forgot your password, you can retrieve your password here.
Password:
Status:
Package:
Bug Type:
Summary:
From: andersena at netscape dot net
New email:
PHP Version: OS:

 

 [2002-08-08 15:35 UTC] andersena at netscape dot net
<?php
$data = array ("Line 1",
"Line 10");
foreach ($data as $subject)
{
$temp = "";
$temp = stripslashes ($subject);
$line = "$temp";
}
?>

The following script causes a seg fault on the second loop iteration.

<?php
$data = array ("Line 1",
"Line 10");
foreach ($data as $subject)
{
$temp = "";
$temp = stripslashes ($subject);
$line = "$temp";
}
?>

Changing any element of the script will make it work properly.

I'm running Mandrake 8.1 on a Gateway E3400, Gateway E-3100, and Dell 2400.

This script segfaults on all of them when using PHP 4.2.2. If I use PHP 4.2.1, everything is fine. It makes no difference whether I'm running a standalone PHP or using Apache 1.3.26. The results are the same.

I use the same PHP.INI file for both versions (I don't replace/change it).

Module information is as follows:

#
# Run 1st time to create apache dynamic module.
# Remove the following if you don't use SSL:
# CPPFLAGS=
#
#cd $HOMEDIR
#tar -xvzf $PHP.tar.gz
#rm -rf $SRC_DIR/$PHP
#mv $PHP $SRC_DIR
#cd $SRC_DIR/$PHP
#CPPFLAGS=-DEAPI \
#./configure  --enable-shared \
#             --enable-track-vars \
#             --enable-versioning \
#             --with-apxs=$APACHEDIR/bin/apxs \
#             --with-config-file-path=/usr/local/lib \
#             --with-mysql \
#             --with-pgsql \
#             --with-sybase=/usr/local/$FREETDS \
#             --with-pdflib=/usr/local \
#             --with-zlib-dir=/usr
#make
#$APACHEDIR/bin/apachectl stop
#make install
#$APACHEDIR/bin/apachectl start
#
# Run 2nd time to create standalone executable.
# The difference between this and the 1st time
# is the CPPFLAGS and --with-apxs, and graphics
# modules to play with.
#
#cd $HOMEDIR
#tar -xvzf $PHP.tar.gz
#rm -rf $SRC_DIR/$PHP
#mv $PHP $SRC_DIR
#cd $SRC_DIR/$PHP
#./configure  --enable-calendar \
#             --enable-dbase \
#             --enable-force-cgi-redirect \
#             --enable-ftp \
#             --with-gd \
#             --with-jpeg-dir=/usr/lib \
#             --enable-shared \
#             --enable-track-vars \
#             --enable-versioning \
#             --with-config-file-path=/usr/local/lib \
#             --with-mysql \
#             --with-pgsql \
#             --with-png-dir=/usr/lib \
#             --with-sybase=/usr/local/$FREETDS \
#             --with-zlib-dir=/usr/lib
#make
#make install

The core dump gives me the following information:

(gdb) bt
#0  0x401dc1da in free () from /lib/libc.so.6
#1  0x401dbf44 in free () from /lib/libc.so.6
#2  0x080f5c43 in shutdown_memory_manager (silent=0, clean_cache=0) at zend_alloc.c:468
#3  0x08066a3a in php_request_shutdown (dummy=0x0) at main.c:794
#4  0x080657cf in main (argc=2, argv=0xbffff7c4) at cgi_main.c:827
#5  0x401775b0 in __libc_start_main () from /lib/libc.so.6
(gdb)

Re-Compiling with --enable-debug results in no core file, and this message:

[Thu Aug  8 12:03:33 2002]  Script:  'test.php'
---------------------------------------
./zend_execute.c(445) : Block 0x082061A8 status:
zend_variables.c(44) : Actual location (location was relayed)
Beginning:      OK (allocated on string.c:2262, 7 bytes)
      End:      Overflown (magic=0x2A8FCC00 instead of 0x2A8FCC84)
                1 byte(s) overflown
---------------------------------------
Content-type: text/html


[Thu Aug  8 12:03:33 2002]  Script:  'test.php'
---------------------------------------
zend_execute_API.c(274) : Block 0x08206708 status:
zend_variables.c(44) : Actual location (location was relayed)
Beginning:      OK (allocated on string.c:2262, 8 bytes)
      End:      Overflown (magic=0x2A8FCC00 instead of 0x2A8FCC84)
                1 byte(s) overflown
---------------------------------------
string.c(2262) :  Freeing 0x0820672C (8 bytes), script=test.php
Last leak repeated 1 time

[EOM]

Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2002-08-08 16:46 UTC] kalowsky@php.net
Please do not submit the same bug more than once. An existing
bug report already describes this very problem. Even if you feel
that your issue is somewhat different, the resolution is likely
to be the same. Because of this, we hope you add your comments
to the original bug instead.

Thank you for your interest in PHP.

Dupe of 18813
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Wed Oct 07 08:00:02 2026 UTC