From:             sergk at sergk dot org dot ua
Operating system: Debian GNU/Linux, kernel 2.6.30
PHP version:      5.2.10
PHP Bug Type:     Reproducible crash
Bug description:  Segfault in function php_curl_option_url

Description:
------------
There is segfault in strncasecmp calling from this code:
curl/interface.c:186 :

if (!strncasecmp("file", uri->scheme, sizeof("file"))) {   
...

when URI is without protocol part hence uri->scheme is NULL.
Like in this example of backtrace:
#0  0xb7e20a8b in strncasecmp () from /lib/i686/cmov/libc.so.6
#1  0xb777dd11 in php_curl_option_url (ch=0x856be00, 
    url=0x856e360
"show.setlinks.ru/?host=SCREENEDHOSTNAME&k=WINDOWS-1251&p=b44eff595164745dee4a6a655a57a425",

    len=<value optimized out>) at
/opt/src/build/apache-1-dweb/dbuild/003d/php-5.2.10/ext/curl/interface.c:187

This bug is also present in last 5.2.x development snapshot.



-- 
Edit bug report at http://bugs.php.net/?id=49372&edit=1
-- 
Try a snapshot (PHP 5.2):            
http://bugs.php.net/fix.php?id=49372&r=trysnapshot52
Try a snapshot (PHP 5.3):            
http://bugs.php.net/fix.php?id=49372&r=trysnapshot53
Try a snapshot (PHP 6.0):            
http://bugs.php.net/fix.php?id=49372&r=trysnapshot60
Fixed in SVN:                        
http://bugs.php.net/fix.php?id=49372&r=fixed
Fixed in SVN and need be documented: 
http://bugs.php.net/fix.php?id=49372&r=needdocs
Fixed in release:                    
http://bugs.php.net/fix.php?id=49372&r=alreadyfixed
Need backtrace:                      
http://bugs.php.net/fix.php?id=49372&r=needtrace
Need Reproduce Script:               
http://bugs.php.net/fix.php?id=49372&r=needscript
Try newer version:                   
http://bugs.php.net/fix.php?id=49372&r=oldversion
Not developer issue:                 
http://bugs.php.net/fix.php?id=49372&r=support
Expected behavior:                   
http://bugs.php.net/fix.php?id=49372&r=notwrong
Not enough info:                     
http://bugs.php.net/fix.php?id=49372&r=notenoughinfo
Submitted twice:                     
http://bugs.php.net/fix.php?id=49372&r=submittedtwice
register_globals:                    
http://bugs.php.net/fix.php?id=49372&r=globals
PHP 4 support discontinued:          http://bugs.php.net/fix.php?id=49372&r=php4
Daylight Savings:                    http://bugs.php.net/fix.php?id=49372&r=dst
IIS Stability:                       
http://bugs.php.net/fix.php?id=49372&r=isapi
Install GNU Sed:                     
http://bugs.php.net/fix.php?id=49372&r=gnused
Floating point limitations:          
http://bugs.php.net/fix.php?id=49372&r=float
No Zend Extensions:                  
http://bugs.php.net/fix.php?id=49372&r=nozend
MySQL Configuration Error:           
http://bugs.php.net/fix.php?id=49372&r=mysqlcfg

Reply via email to