php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #17764 crash in ereg_replace (with patch to fix it ;-)
Submitted: 2002-06-14 10:39 UTC Modified: 2002-06-17 11:13 UTC
From: oliver at billix dot franken dot de Assigned:
Status: Closed Package: Reproducible crash
PHP Version: 4.2.1 OS: Linux 2.2.19
Private report: No CVE-ID: None
 [2002-06-14 10:39 UTC] oliver at billix dot franken dot de
I wanted to replace any umlauts with strings (not chars in octal...) like "\200". I used ereg_replace for this and it worked until PHP 4.2.0 was released. Than php just crashed. I now know there are better solutions to accomplish this, e.g. str_replace... But on the other hand, php shouldn't crash on user input...

Here is the code:

<?php
  $x = "a?b?c";
  $x = ereg_replace ( "?" , "\\200" , $x );
  print "$x\n";
  $x = ereg_replace ( "?" , "\\234" , $x );
  print "$x\n";
?>

The problem is, \\2 is taken as an index into an array, which has only one element. The fix is easy, just check the digit if it is a valid index:

--- reg.c       Sun May  5 10:39:57 2002
+++ reg.c.new   Fri Jun 14 16:13:38 2002
@@ -341,6 +341,7 @@
                        while (*walk)
                                if ('\\' == *walk
                                        && '0' <= walk[1] && '9' >= walk[1]
+                                       && walk[1] - '0' <= re.re_nsub
                                        && subs[walk[1] - '0'].rm_so > -1
                                        && subs[walk[1] - '0'].rm_eo > -1) {
                                        new_l += subs[walk[1] - '0'].rm_eo
@@ -368,6 +369,7 @@
                        while (*walk)
                                if ('\\' == *walk
                                        && '0' <= walk[1] && '9' >= walk[1]
+                                       && walk[1] - '0' <= re.re_nsub
                                        && subs[walk[1] - '0'].rm_so > -1
                                        && subs[walk[1] - '0'].rm_eo > -1
                                        /* this next case shouldn't happen. it does. */

Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2002-06-17 11:13 UTC] andrei@php.net
This bug has been fixed in CVS. You can grab a snapshot of the
CVS version at http://snaps.php.net/. In case this was a documentation 
problem, the fix will show up soon at http://www.php.net/manual/.
In case this was a PHP.net website problem, the change will show
up on the PHP.net site and on the mirror sites.
Thank you for the report, and for helping us make PHP better.


 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Wed Oct 07 13:00:02 2026 UTC