Bug #66311 [Opn->Csd]: Stack smashing protection kills PDO/ODBC queries
| From: | felipe@php.net | Date: | Sun, 22 Dec 2013 11:43:04 +0000 |
| Subject: | Bug #66311 [Opn->Csd]: Stack smashing protection kills PDO/ODBC queries | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-183432@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=66311&edit=1
ID: 66311
Updated by: felipe@php.net
Reported by: michael at orlitzky dot com
Summary: Stack smashing protection kills PDO/ODBC queries
-Status: Open
+Status: Closed
Type: Bug
Package: ODBC related
Operating System: Gentoo Linux
PHP Version: master-Git-2013-12-17 (Git)
-Assigned To:
+Assigned To: felipe
Block user comment: N
Private report: N
New Comment:
The fix for this bug has been committed.
Snapshots of the sources are packaged every three hours; this change
will be in the next snapshot. You can grab the snapshot at
http://snaps.php.net/.
For Windows:
http://windows.php.net/snapshots/
Thank you for the report, and for helping us make PHP better.
Previous Comments:
------------------------------------------------------------------------
[2013-12-17 20:06:14] michael at orlitzky dot com
Description:
------------
The background and test code for the issue can be found at,
https://bugs.gentoo.org/show_bug.cgi?id=491100
In ext/pdo_odbc/odbc_stmt.c, there is a function odbc_stmt_describe which declares variables,
SDWORD colsize, displaysize;
Later the displaysize variable is filled via a call to SQLColAttribute:
rc = SQLColAttribute(S->stmt, colno+1,
SQL_DESC_DISPLAY_SIZE,
NULL, 0, NULL, &displaysize);
According to /usr/include/sqlucode.h, the final parameter to SQLColAttribute should be of type
SQLLEN instead of SDWORD. When displaysize's value is finally used,
colsize = displaysize;
col->maxlen = S->cols[colno].datalen = colsize;
The stack smashing protection kicks in due to the mismatched types, and the program segfaults.
Replacing the SDWORD type with SQLLEN avoids the issue (although there are other type warnings in
the same file).
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=66311&edit=1