Bug #68881 [Asn->Nab]: null pointer dereference / unused function

From: Date: Mon, 02 Feb 2015 08:12:19 +0000
Subject: Bug #68881 [Asn->Nab]: null pointer dereference / unused function
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-190398@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68881&edit=1 ID: 68881 Updated by: yohgaki@php.net Reported by: bugreports at internot dot info Summary: null pointer dereference / unused function -Status: Assigned +Status: Not a bug Type: Bug Package: Session related Operating System: any PHP Version: master-Git-2015-01-22 (Git) Assigned To: yohgaki Block user comment: N Private report: N New Comment: I checked source and it cannot be null. The unused function seems intended for external modules, so I made it useable. http://git.php.net/?p=php-src.git;a=commitdiff;h=f248df900300c5b2201d4cf634d58d413399e2eb Previous Comments: ------------------------------------------------------------------------ [2015-01-22 08:42:51] yohgaki@php.net I mean "It's supposed to work" ------------------------------------------------------------------------ [2015-01-22 08:41:59] yohgaki@php.net Thank you for the insight. I'll check see if trans sid works (I supposed to work). ------------------------------------------------------------------------ [2015-01-22 07:49:50] bugreports at internot dot info I can't find where it is used: megamansec@megamansec:~/php-src$ grep -nr 'session_adapt_url' ext/session/session.c:1609:PHPAPI void session_adapt_url(const char *url, size_t urllen, char **new, size_t *newlen) /* {{{ */ ext/session/php_session.h:224:PHPAPI void session_adapt_url(const char *, size_t, char **, size_t *); megamansec@megamansec:~/php-src$ Is it not in master anymore? Thanks, ------------------------------------------------------------------------ [2015-01-22 05:26:11] yohgaki@php.net session_adapt_url() or php_url_scanner_adapt_single_url() is used for trans sid. i.e. session.use_trans_sid = 1. With a quick look, the buf could be NULL when there is no inputs. (This would only happens with zend_smart_str, I suppose) I don't use trans sid at all. Could you make a simple reproducible test script? Please don't forget to send your INI setting. ------------------------------------------------------------------------ [2015-01-22 04:04:02] bugreports at internot dot info Description: ------------ Hi, Is the session_adapt_url function ever used? Or, php_url_scanner_adapt_single_url? Inside php_url_scanner_adapt_single_url there is a null pointer dereference: 389 if (newlen) *newlen = buf.s->len; 390 result = estrndup(buf.s->val, buf.s->len); but it is initalized with {0}. The function isn't used anywhere, though. Should it be removed? ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=68881&edit=1

« previous php.bugs (#190398) next »