Bug #66049 [Com]: Typemap can break parsing in parse_packet_soap leading to a segfault

From: Date: Fri, 08 Nov 2013 17:54:09 +0000
Subject: Bug #66049 [Com]: Typemap can break parsing in parse_packet_soap leading to a segfault
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-182666@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=66049&edit=1 ID: 66049 Comment by: martin dot koegler at brz dot gv dot at Reported by: martin dot koegler at brz dot gv dot at Summary: Typemap can break parsing in parse_packet_soap leading to a segfault Status: Open Type: Bug Package: SOAP related Operating System: Any PHP Version: 5.5.5 Block user comment: N Private report: N New Comment: Workaround: --- php-5.5.5/ext/soap/php_packet_soap.c.orig 2013-11-08 13:47:42.100530545 +0100 +++ php-5.5.5/ext/soap/php_packet_soap.c 2013-11-08 13:49:00.252852632 +0100 @@ -192,6 +192,7 @@ tmp = get_node(fault->children, "faultstring"); if (tmp != NULL && tmp->children != NULL) { zval *zv = master_to_zval(get_conversion(IS_STRING), tmp TSRMLS_CC); + convert_to_string_ex(&zv); faultstring = Z_STRVAL_P(zv); FREE_ZVAL(zv); } @@ -199,6 +200,7 @@ tmp = get_node(fault->children, "faultactor"); if (tmp != NULL && tmp->children != NULL) { zval *zv = master_to_zval(get_conversion(IS_STRING), tmp TSRMLS_CC); + convert_to_string_ex(&zv); faultactor = Z_STRVAL_P(zv); FREE_ZVAL(zv); } @@ -222,6 +224,7 @@ tmp = get_node(tmp->children,"Text"); if (tmp != NULL && tmp->children != NULL) { zval *zv = master_to_zval(get_conversion(IS_STRING), tmp TSRMLS_CC); + convert_to_string_ex(&zv); faultstring = Z_STRVAL_P(zv); FREE_ZVAL(zv); } Previous Comments: ------------------------------------------------------------------------ [2013-11-07 17:55:14] martin dot koegler at brz dot gv dot at Description: ------------ parse_packet_soap extracts various data from the response with the following sequence: zval *zv = master_to_zval(get_conversion(IS_STRING), tmp TSRMLS_CC); faultstring = Z_STRVAL_P(zv); It assumes, that zv contains a string, but a typemap allow master_to_zval to return a different type. Accessing that a different type as string usually least to a segfault via parse_packet_soap => add_soap_fault => set_soap_fault => add_property_string_ex => crash in strlen Easiest workaround is to force the string data type via convert_to_string_ex(&zv); before accessing Z_STRVAL_P(zv). Test script: --------------- Take any wsdl as test.wsdl and point it to server.php as URL. Adapt client.php to call a existing operation of the wsdl: client.php: <?php function soap_string_from_xml($str) { return new stdClass(); } $client=new soapclient("test.wsdl", array('typemap'=>array( array("type_ns"=>"http://www.w3.org/2001/XMLSchema", "type_name"=>"string", "from_xml"=>"soap_string_from_xml") ))); $client->Mist(""); ?> server.php: <?php header("Content-Type: text/xml"); header("HTTP/1.0 500 Internal Error");?> <?xml version="1.0" encoding="UTF-8"?> <SOAP-ENV:Envelope xmlns:SOAP-ENV="http://schemas.xmlsoap.org/soap/envelope/"><SOAP-ENV:Body><SOAP-ENV:Fault><faultcode>SOAP-ENV:Server</faultcode><faultstring>not present</faultstring></SOAP-ENV:Fault></SOAP-ENV:Body></SOAP-ENV:Envelope> ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=66049&edit=1

« previous php.bugs (#182666) next »