Bug #67134 [Opn->Csd]: missing null terminator for uniqueidentifier value

From: Date: Tue, 21 Oct 2014 04:46:04 +0000
Subject: Bug #67134 [Opn->Csd]: missing null terminator for uniqueidentifier value
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-188218@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=67134&edit=1 ID: 67134 Updated by: ssufficool@php.net Reported by: kaido at tradenet dot ee Summary: missing null terminator for uniqueidentifier value -Status: Open +Status: Closed Type: Bug Package: PDO DBlib Operating System: debian PHP Version: 5.4Git-2014-04-26 (Git) Block user comment: N Private report: N New Comment: Automatic comment on behalf of ssufficool Revision: http://git.php.net/?p=php-src.git;a=commit;h=09cf64678a76fbbe9eb897a128b65dc5618f2ad1 Log: Fix bug #67134 (PDO_DBLIB Missing null string terminator) Previous Comments: ------------------------------------------------------------------------ [2014-04-26 09:01:24] kaido at tradenet dot ee The bug is in ext/pdo_dblib/dblib_stmt.c: pdo_dblib_stmt_get_col() current code: case SQLUNIQUE: { *len = 36+1; tmp_ptr = emalloc(*len + 1); /* uniqueidentifier is a 16-byte binary number, convert to 32 char hex string */ *len = dbconvert(NULL, SQLUNIQUE, *ptr, *len, SQLCHAR, tmp_ptr, *len); php_strtoupper(tmp_ptr, *len); *ptr = tmp_ptr; break; } the length is correctly set to 36+1 (reserving 1 for the null terminator), but the terminator itselt is not set. Also, the comment there is outdated and no longer relevant, so removed. the code should be as follows: case SQLUNIQUE: { *len = 36+1; tmp_ptr = emalloc(*len + 1); *len = dbconvert(NULL, SQLUNIQUE, *ptr, *len, SQLCHAR, tmp_ptr, *len); php_strtoupper(tmp_ptr, *len); tmp_ptr[36] = '\0'; *ptr = tmp_ptr; break; Can someome with better knowledge of the code confirm my observations, and commit the fix, please. ------------------------------------------------------------------------ [2014-04-26 08:56:43] kaido at tradenet dot ee Description: ------------ PHP 5.4.29-dev (cli) (built: Apr 24 2014 16:49:28) (DEBUG) Copyright (c) 1997-2014 The PHP Group Zend Engine v2.4.0, Copyright (c) 1998-2014 Zend Technologies pdo_dblib does not set null terminator for returned uniqueidentifier column Test script: --------------- <?php $dsn = "dblib:host=xxx.xxx.xxx;dbname=xxx"; $pdo = new PDO($dsn, 'xxxx', 'xxxx'); $stmt = $pdo->query('select newid() '); $res = $stmt->fetch(); var_dump($res); unset ($stmt); ?> Expected result: ---------------- array(2) { [""]=> string(36) "29E3B7BD-63DD-47C5-B58C-E41F12E4CAE3" [0]=> string(36) "29E3B7BD-63DD-47C5-B58C-E41F12E4CAE3" } Actual result: -------------- array(2) { [""]=> string(36) "29E3B7BD-63DD-47C5-B58C-E41F12E4CAE3" [0]=> string(36) "29E3B7BD-63DD-47C5-B58C-E41F12E4CAE3" } Warning: String is not zero-terminated (29E3B7BD-63DD-47C5-B58C-E41F12E4CAE3 ) (source: /root/php/php-src/Zend/zend_execute_API.c:436) in Unknown on line 0 ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=67134&edit=1

« previous php.bugs (#188218) next »