php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #18140 Array key -1 can crash PHP
Submitted: 2002-07-03 11:50 UTC Modified: 2002-08-01 12:07 UTC
From: carl at thep dot lu dot se Assigned:
Status: Closed Package: Scripting Engine problem
PHP Version: 4.3.0-dev OS: Linux
Private report: No CVE-ID: None
 [2002-07-03 11:50 UTC] carl at thep dot lu dot se
If the last key of an array with at least 2 elements is -1,
adding new elements with [] (or array_push) crashes PHP.
Here is the simplest example I could create:

   $arr = array(0=>0,-1=>0);
   $arr[] = 0;

I haven't tested with the CVS version.

Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2002-07-03 12:35 UTC] sander@php.net
Thank you for this bug report. To properly diagnose the problem, we
need a backtrace to see what is happening behind the scenes. To
find out how to generate a backtrace, please read
http://bugs.php.net/bugs-generating-backtrace.php

Once you have generated a backtrace, please submit it to this bug
report and change the status back to "Open". Thank you for helping
us make PHP better.

Can't reproduce with latest CVS. Can you try the CVS version and generate a backtrace if possible?
 [2002-07-03 13:16 UTC] jan@php.net
vrified on FreeBSD

#0  zend_fetch_dimension_address (result=0x81e7178, op1=0x81e7188, op2=0x81e7198, Ts=0xbfbfe6e8, type=1)
    at /mnt/data/cvs/php4/Zend/zend_execute_locks.h:8
8               z->refcount++;
(gdb) bt
#0  zend_fetch_dimension_address (result=0x81e7178, op1=0x81e7188, op2=0x81e7198, Ts=0xbfbfe6e8, type=1)
    at /mnt/data/cvs/php4/Zend/zend_execute_locks.h:8
#1  0x8127e0d in execute (op_array=0x81da68c) at /mnt/data/cvs/php4/Zend/zend_execute.c:1263
#2  0x811c0a0 in zend_execute_scripts (type=8, retval=0x0, file_count=3) at /mnt/data/cvs/php4/Zend/zend.c:810
#3  0x80fca4a in php_execute_script (primary_file=0xbfbffb1c) at /mnt/data/cvs/php4/main/main.c:1376
#4  0x81314dd in main (argc=2, argv=0xbfbffb84) at /mnt/data/cvs/php4/sapi/cli/php_cli.c:674
#5  0x80611c9 in _start ()

 [2002-07-03 13:21 UTC] sniper@php.net
Reproduced with latest CVS HEAD on Linux.

 [2002-07-29 09:31 UTC] nohn@php.net
Verified with 4.3.0-dev on Compaq Tru64/Alpha (CLI) and 4.2.0 on Solaris 7/Sparc (Apache) 
 [2002-08-01 12:07 UTC] stas@php.net
This bug has been fixed in CVS. You can grab a snapshot of the
CVS version at http://snaps.php.net/. In case this was a documentation 
problem, the fix will show up soon at http://www.php.net/manual/.
In case this was a PHP.net website problem, the change will show
up on the PHP.net site and on the mirror sites.
Thank you for the report, and for helping us make PHP better.


 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Wed Oct 07 22:00:01 2026 UTC