Bug #67134 [Opn->Csd]: missing null terminator for uniqueidentifier value
| From: | ssufficool@php.net | Date: | Tue, 21 Oct 2014 04:46:04 +0000 |
| Subject: | Bug #67134 [Opn->Csd]: missing null terminator for uniqueidentifier value | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-188218@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=67134&edit=1
ID: 67134
Updated by: ssufficool@php.net
Reported by: kaido at tradenet dot ee
Summary: missing null terminator for uniqueidentifier value
-Status: Open
+Status: Closed
Type: Bug
Package: PDO DBlib
Operating System: debian
PHP Version: 5.4Git-2014-04-26 (Git)
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of ssufficool
Revision: http://git.php.net/?p=php-src.git;a=commit;h=09cf64678a76fbbe9eb897a128b65dc5618f2ad1
Log: Fix bug #67134 (PDO_DBLIB Missing null string terminator)
Previous Comments:
------------------------------------------------------------------------
[2014-04-26 09:01:24] kaido at tradenet dot ee
The bug is in ext/pdo_dblib/dblib_stmt.c: pdo_dblib_stmt_get_col()
current code:
case SQLUNIQUE: {
*len = 36+1;
tmp_ptr = emalloc(*len + 1);
/* uniqueidentifier is a 16-byte binary number, convert to 32 char hex
string */
*len = dbconvert(NULL, SQLUNIQUE, *ptr, *len, SQLCHAR, tmp_ptr, *len);
php_strtoupper(tmp_ptr, *len);
*ptr = tmp_ptr;
break;
}
the length is correctly set to 36+1 (reserving 1 for the null terminator), but the terminator itselt
is not set. Also, the comment there is outdated and no longer relevant, so removed.
the code should be as follows:
case SQLUNIQUE: {
*len = 36+1;
tmp_ptr = emalloc(*len + 1);
*len = dbconvert(NULL, SQLUNIQUE, *ptr, *len, SQLCHAR, tmp_ptr, *len);
php_strtoupper(tmp_ptr, *len);
tmp_ptr[36] = '\0';
*ptr = tmp_ptr;
break;
Can someome with better knowledge of the code confirm my observations, and commit the fix, please.
------------------------------------------------------------------------
[2014-04-26 08:56:43] kaido at tradenet dot ee
Description:
------------
PHP 5.4.29-dev (cli) (built: Apr 24 2014 16:49:28) (DEBUG)
Copyright (c) 1997-2014 The PHP Group
Zend Engine v2.4.0, Copyright (c) 1998-2014 Zend Technologies
pdo_dblib does not set null terminator for returned uniqueidentifier column
Test script:
---------------
<?php
$dsn = "dblib:host=xxx.xxx.xxx;dbname=xxx";
$pdo = new PDO($dsn, 'xxxx', 'xxxx');
$stmt = $pdo->query('select newid() ');
$res = $stmt->fetch();
var_dump($res);
unset ($stmt);
?>
Expected result:
----------------
array(2) {
[""]=>
string(36) "29E3B7BD-63DD-47C5-B58C-E41F12E4CAE3"
[0]=>
string(36) "29E3B7BD-63DD-47C5-B58C-E41F12E4CAE3"
}
Actual result:
--------------
array(2) {
[""]=>
string(36) "29E3B7BD-63DD-47C5-B58C-E41F12E4CAE3"
[0]=>
string(36) "29E3B7BD-63DD-47C5-B58C-E41F12E4CAE3"
}
Warning: String is not zero-terminated (29E3B7BD-63DD-47C5-B58C-E41F12E4CAE3 ) (source:
/root/php/php-src/Zend/zend_execute_API.c:436) in Unknown on line 0
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=67134&edit=1