Return-Path: <mslifcak@iss.net>
Delivered-To: sas@flaubert.foo.bar
Received: (qmail 832 invoked from network); 5 Apr 1999 18:13:56 -0000
Received: from guerilla.foo.bar (192.168.0.1)
  by flaubert.foo.bar with SMTP; 5 Apr 1999 18:13:56 -0000
Received: (qmail 886 invoked by uid 1000); 5 Apr 1999 20:14:09 +0200
Delivered-To: sas@localhost
Received: (qmail 883 invoked from network); 5 Apr 1999 20:14:09 +0200
Received: from localhost.foo.bar (HELO localhost) (127.0.0.1)
  by localhost.foo.bar with SMTP; 5 Apr 1999 20:14:09 +0200
Received: from 194.195.194.253
	by fetchmail-4.6.3 POP3
	for <sas/localhost> (single-drop); Mon, 05 Apr 1999 20:14:09 CEST
Received: from leya.schell.de (bausatz.de [195.63.245.131] (may be forged))
	by mail.iserlohn.netsurf.de (8.9.1/8.9.1) with SMTP id UAA10486
	for <s.schuma@iserlohn.netsurf.de>; Mon, 5 Apr 1999 20:12:10 +0200
Received: (qmail 8168 invoked by alias); 5 Apr 1999 20:11:39 +0200
Received: (qmail 8159 invoked by alias); 5 Apr 1999 20:11:38 +0200
Delivered-To: alias-sas-sascha@schumann.2ns.de
Received: (qmail 8155 invoked from network); 5 Apr 1999 20:11:38 +0200
Received: from polz.de (HELO sockratte.schell.de) (qmailr@195.20.238.74)
  by bausatz.de with SMTP; 5 Apr 1999 20:11:38 +0200
Received: (qmail 32054 invoked from network); 5 Apr 1999 20:11:37 +0200
Received: from loki.iss.net (root@208.21.0.3)
  by polz.de with SMTP; 5 Apr 1999 20:11:37 +0200
Received: from warble (warble.iss.net [208.21.2.107])
	by loki.iss.net (8.9.3/8.9.3) with SMTP id OAA05600;
	Mon, 5 Apr 1999 14:09:53 -0400
Message-Id: <3.0.1.32.19990405141648.0090e3c0@mail.iss.net>
X-Sender: mslifcak@mail.iss.net
X-Mailer: Windows Eudora Pro Version 3.0.1 (32)
Date: Mon, 05 Apr 1999 14:16:48 -0400
To: Joe Marzot <gmarzot@nortelnetworks.com>, sascha@schumann.2ns.de
From: "Michael J. Slifcak" <mslifcak@iss.net>
Subject: [PHP-DEV] Re: 3.6.1: snmp_close frees community string passed to
  snmp_open
Cc: ucd-snmp-coders@bandit.ucdavis.edu
In-Reply-To: <pdu2uv5bbc.fsf@baynetworks.com>
References: <sascha@schumann.2ns.de's message of "3 Apr 1999 17:58:37 -0000">
 <19990403175837.6349.qmail@flaubert.foo.bar>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
X-UIDL: 7b5d8c9faefe7956397c46aef5f444f3

Joe's fix works just fine.  It will be included in the next release.
Sorry for the inconvenience that NO_ZEROLENGTH_COMMUNITY may have caused.

-Mike Slifcak
Internet Security Systems, Inc.

At 11:36 AM 4/5/99 -0400, Joe Marzot wrote:
>sascha@schumann.2ns.de writes:
>
>> UCD-SNMP version 3.6.1 bug report
>> ----------------------------------------------------------
>> 
>> I'm one of the PHP3 developers and I'm currently trying to track down, if a
>> SNMP related bug is on our side or on yours.
>> 
>> We provide a simple way to get SNMP objects and as such need to open a
session.
>> We pass snmp_open() a pointer to a struct session which holds pointer to
our
>> private data.
>> 
>> But, unless NO_ZEROLENGTH_COMMUNITY is defined at compile time, the
pointer to
>> the community string is only copied in snmp_sess_open() and freed
afterwards in
>> snmp_close().
>> 
>> There is no notice of this in the documentation and IMO a library should
not
>> free data it has not allocated. Are we missing something? 
>> 
>> Regards, 
>>  
>>    Sascha Schumann
>
>looks like a bug to me. The current 3.6.1 code does the following
>#ifdef NO_ZEROLENGTH_COMMUNITY
>    /* Fill in defaults if necessary */
>    if (session->community_len != SNMP_DEFAULT_COMMUNITY_LEN){
>        cp = (u_char *)malloc((unsigned)session->community_len);
>        if (cp)
>        memmove(cp, session->community, session->community_len);
>    } else {
>        session->community_len = strlen(DEFAULT_COMMUNITY);
>        cp = (u_char *)malloc((unsigned)session->community_len);
>        if (cp)
>        memmove(cp, DEFAULT_COMMUNITY, session->community_len);
>    }
>
>    if (cp == NULL) {
>      snmp_errno = SNMPERR_GENERR;
>      in_session->s_snmp_errno = SNMPERR_GENERR;
>      snmp_sess_close(slp);
>      return(NULL);
>    }
>
>    session->community = cp;    /* replace pointer with pointer to new
data */
>#endif /* NO_ZEROLENGTH_COMMUNITY */
>
>perhaps something like this would be better
>
>    /* Fill in defaults if necessary */
>    if (session->community_len != SNMP_DEFAULT_COMMUNITY_LEN){
>        cp = (u_char *)malloc((unsigned)session->community_len);
>        if (cp)
>        memmove(cp, session->community, session->community_len);
>    } else {
>#ifdef NO_ZEROLENGTH_COMMUNITY
>        session->community_len = strlen(DEFAULT_COMMUNITY);
>        cp = (u_char *)malloc((unsigned)session->community_len);
>        if (cp) memmove(cp, DEFAULT_COMMUNITY, session->community_len);
>#else
>        cp = strdup("");
>#endif
>    }
>
>    if (cp == NULL) {
>      snmp_errno = SNMPERR_GENERR;
>      in_session->s_snmp_errno = SNMPERR_GENERR;
>      snmp_sess_close(slp);
>      return(NULL);
>    }
>
>    session->community = cp;    /* replace pointer with pointer to new
data */
>
>-GSM
>
>-- 
>G.S. Marzot                        email: gmarzot@nortelnetworks.com
>Nortel Networks                    voice: (978)916-3990
>600 Tech Park  M/S BL60-101        pager: (800)409-6080 (4096080@skytel.com)
>Billerica, MA  01821                 fax: (978)670-8145

