#50370 [Opn]: 64bit libtdsodbc.so crash because of malloc 4 byte missing
| From: | nalply at gmail dot com | Date: | Thu, 03 Dec 2009 08:41:30 +0000 |
| Subject: | #50370 [Opn]: 64bit libtdsodbc.so crash because of malloc 4 byte missing | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-145361@lists.php.net to get a copy of this message | ||
ID: 50370
User updated by: nalply at gmail dot com
Reported By: nalply at gmail dot com
Status: Open
Bug Type: Reproducible crash
Operating System: Debian Lenny amd64
PHP Version: 5.2.11
New Comment:
The link does not work (it is too long). Use this instead:
http://bit.ly/7e028s
Previous Comments:
------------------------------------------------------------------------
[2009-12-03 08:39:52] nalply at gmail dot com
Description:
------------
I have a page which reproducibly overwrites non alloc'd memory (a write
of 8 bytes instead of 4 bytes at the end of the range). It is caused by
the call odbc_fetch_object() and the bad write in libtdsodbc.so.
For more details see:
http://serverfault.com/questions/90100/64bit-unixodbc-and-freetds-a-bug-in-libtdsodbc-so,
there is a valgrind output.
It crashes in the Apache module only. The PHP command line with Suhosin
reports a canary mismatch.
Note, it is version 5.2.6-1+lenny4, that's what Debian Lenny has
installed, and not 5.2.11, because the form forced me to enter this
version. I won't upgrade my PHP to a newer version. Take this bug report
or leave it.
It is not sure whether the bug is in PHP ODBC or in TDS ODBC, so I am
going to report this bug thrice: here and there and with Debian.
Reproduce code:
---------------
#!/usr/bin/php5
<?php
$conn = odbc_connect("dsn", "user", "password");
$query = odbc_exec($conn, "SELECT 'alpha' test");
echo "Before odbc_fetch_object(); query=$query\n"; flush();
if ($query) $row = odbc_fetch_object($query);
echo "After odbc_fetch_row();\n"; flush();
echo "Result=" . $row->test . "\n";
?>some static text
Expected result:
----------------
Before odbc_fetch_object(); query=Resource id #5
After odbc_fetch_row();
Result=alpha
some static text
ALERT - canary mismatch on efree() - heap overflow detected (attacker
'REMOTE_ADDR not set', file 'unknown')
Actual result:
--------------
Before odbc_fetch_object(); query=Resource id #5
After odbc_fetch_row();
Result=alpha
some static text
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=50370&edit=1