From 216784bcc32218539591eb804f3b0ec93cc83b22 Mon Sep 17 00:00:00 2001 From: Moriyoshi Koizumi Date: Fri, 4 Apr 2003 09:11:28 +0000 Subject: [PATCH] segfault busting news replacing one tab to 4 spaces --- TODO_SEGFAULTS | 11 ++--------- 1 file changed, 2 insertions(+), 9 deletions(-) diff --git a/TODO_SEGFAULTS b/TODO_SEGFAULTS index 04219430ff..00ab6a5dd7 100644 --- a/TODO_SEGFAULTS +++ b/TODO_SEGFAULTS @@ -19,12 +19,12 @@ Fixed: ob_start (Sascha) imagecreate/-truecolor (Sascha) flock (Sascha) - register_shutdown_function (Sascha) + register_shutdown_function (Sascha) + mb_strcut('', [number greater than the length of first arg]) (Moriyoshi) Open: the dbase extension (1) - mb_strcut('', 2147483647); (2) chunk_split (3) socket_select (4) php_imagepolygon (5) @@ -49,13 +49,6 @@ dbase_numrecords dbase_open X -(2) backtrace: -#0 0x080b828e in mbfl_strcut (string=0xbfffbde0, result=0xbfffbdd0, - from=2147483647, length=0) - at /home/sas/src/php4/ext/mbstring/mbfilter.c:8258 - 8258 (*encoder->filter_function)(*p++, encoder TSRMLS_CC); - - (3) integer overflow in php_chunk_split (4) heap corruption, dies in efree()/execute() -- 2.50.1