Req #67343 [NEW]: date/lib/parse_date.c does not check *allocs
| From: | al-phpbug at none dot at | Date: | Mon, 26 May 2014 12:52:42 +0000 |
| Subject: | Req #67343 [NEW]: date/lib/parse_date.c does not check *allocs | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-185927@lists.php.net to get a copy of this message | ||
From: al-phpbug at none dot at
Operating system: all
PHP version: 5.5.12
Package: Date/time related
Bug Type: Feature/Change Request
Bug description:date/lib/parse_date.c does not check *allocs
Description:
------------
According to point 9 of php-5.5.12/CODING_STANDARDS the parse_date does
not use the emalloc(), efree(), estrdup(), etc. and it does not check if
the *alloc was successfully
egrep -A3 alloc php-5.5.12/ext/date/lib/parse_date.c
#######
uchar *buf = (uchar*) malloc(((s->lim - s->bot) +
BSIZE)*sizeof(uchar));
memcpy(buf, s->tok, s->lim - s->tok);
s->tok = buf;
s->ptr = &buf[s->ptr - s->bot];
--
s->errors->warning_messages = realloc(s->errors->warning_messages,
s->errors->warning_count * sizeof(timelib_error_message));
s->errors->warning_messages[s->errors->warning_count - 1].position =
s->tok ? s->tok - s->str : 0;
s->errors->warning_messages[s->errors->warning_count - 1].character =
s->tok ? *s->tok : 0;
s->errors->warning_messages[s->errors->warning_count - 1].message =
strdup(error);
--
s->errors->error_messages = realloc(s->errors->error_messages,
s->errors->error_count * sizeof(timelib_error_message));
s->errors->error_messages[s->errors->error_count - 1].position = s->tok
? s->tok - s->str : 0;
s->errors->error_messages[s->errors->error_count - 1].character =
s->tok ? *s->tok : 0;
s->errors->error_messages[s->errors->error_count - 1].message =
strdup(error);
--
s->errors->warning_messages = realloc(s->errors->warning_messages,
s->errors->warning_count * sizeof(timelib_error_message));
s->errors->warning_messages[s->errors->warning_count - 1].position =
cptr - sptr;
s->errors->warning_messages[s->errors->warning_count - 1].character =
*cptr;
s->errors->warning_messages[s->errors->warning_count - 1].message =
strdup(error);
--
s->errors->error_messages = realloc(s->errors->error_messages,
s->errors->error_count * sizeof(timelib_error_message));
s->errors->error_messages[s->errors->error_count - 1].position = cptr -
sptr;
s->errors->error_messages[s->errors->error_count - 1].character =
*cptr;
s->errors->error_messages[s->errors->error_count - 1].message =
strdup(error);
--
char *tmp = calloc(1, s->cur - s->tok + 1);
memcpy(tmp, s->tok, s->cur - s->tok);
return tmp;
--
str = calloc(1, end - begin + 1);
memcpy(str, begin, end - begin);
tmp_nr = strtoll(str, NULL, 10);
free(str);
--
str = calloc(1, end - begin + 1);
memcpy(str, begin, end - begin);
if (str[0] == ':') {
str[0] = '.';
--
word = calloc(1, end - begin + 1);
memcpy(word, begin, end - begin);
for (tp = timelib_reltext_lookup; tp->name; tp++) {
--
word = calloc(1, end - begin + 1);
memcpy(word, begin, end - begin);
for (tp = timelib_month_lookup; tp->name; tp++) {
--
word = calloc(1, end - begin + 1);
memcpy(word, begin, end - begin);
for (tp = timelib_relunit_lookup; tp->name; tp++) {
--
word = calloc(1, end - begin + 1);
memcpy(word, begin, end - begin);
if ((tp = zone_search(word, -1, 0))) {
--
in.errors = malloc(sizeof(struct timelib_error_container));
in.errors->warning_count = 0;
in.errors->warning_messages = NULL;
in.errors->error_count = 0;
--
in.str = malloc((e - s) + YYMAXFILL);
memset(in.str, 0, (e - s) + YYMAXFILL);
memcpy(in.str, s, (e - s));
in.lim = in.str + (e - s) + YYMAXFILL;
--
in.errors = malloc(sizeof(struct timelib_error_container));
in.errors->warning_count = 0;
in.errors->warning_messages = NULL;
in.errors->error_count = 0;
#######
Maybe it is unimportant but it would be nice if anyone take a look there
and say it's ok or not.
I think the whole date directory should be reviewed.
egrep -r -A3 alloc php-5.5.12/ext/date/*
--
Edit bug report at https://bugs.php.net/bug.php?id=67343&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=67343&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=67343&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=67343&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=67343&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=67343&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=67343&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=67343&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=67343&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=67343&r=support
Expected behavior: https://bugs.php.net/fix.php?id=67343&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=67343&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=67343&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=67343&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=67343&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=67343&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=67343&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=67343&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=67343&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=67343&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=67343&r=mysqlcfg