Bug #68350 [Opn]: SQL_DESC_OCTET_LENGTH not supported by ADS ODBC driver

From: Date: Fri, 17 Apr 2015 19:00:57 +0000
Subject: Bug #68350 [Opn]: SQL_DESC_OCTET_LENGTH not supported by ADS ODBC driver
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-192170@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68350&edit=1

 ID:                 68350
 Updated by:         ab@php.net
 Reported by:        frederic dot marchal at wowtechnology dot com
 Summary:            SQL_DESC_OCTET_LENGTH not supported by ADS ODBC
                     driver
 Status:             Open
 Type:               Bug
 Package:            ODBC related
 PHP Version:        5.4.34
 Block user comment: N
 Private report:     N

 New Comment:

@frederic, if it's fixed with #69354 as well - so that's great. The subsequent fixes to
the ext/odbc in the 5.5 branch could be of some interest for you, as well. 

I think it's hardly going into 5.4 though, as it's more about ODBC 3.0 support and not
security. So probably you've two ways - either upgrading to at least 5.5 or patching 5.4
manually. Anyway seems this ticket is done now, please close it by chance.

Thanks.


Previous Comments:
------------------------------------------------------------------------
[2015-04-15 13:37:23] frederic dot marchal at wowtechnology dot com

The patch https://github.com/php/php-src/commit/b3a027d6103b69bb935431dbec2e59eb20454862
solves the problem for the ADS ODBC driver too.

Simply replacing SQLColAttributes with SQLColAttribute (without 's') does the trick.

So, this bug is similar to bug #69354 and the solution proposed there is better than my patch as it
addresses the cause of the problem instead of working around it.

------------------------------------------------------------------------
[2015-04-14 20:00:48] cmb@php.net

Might be related to bug #69354.

------------------------------------------------------------------------
[2015-04-11 17:55:46] cmb@php.net

Due to bug #68087 SQL_DESC_OCTET_LENGTH could have been applied for
other fields than SQL_*CHAR, which is likely to fail. The
respective fix[1] resolved this issue. For drivers not recognizing
SQL_DESC_OCTET_LENGTH for SQL_*CHAR fields, of course that wouldn't
help.

I'm unassigning myself, so someone else with access to an ADS and
php-src karma can pick up.

[1] <https://github.com/php/php-src/commit/df9078ea55e2bd60d718c6e6948b70311650fe39>

------------------------------------------------------------------------
[2015-04-11 17:21:49] frederic dot marchal at wowtechnology dot com

I assume this is the very last php_odbc.c file:

https://github.com/php/php-src/blob/master/ext/odbc/php_odbc.c

Then, no, the problem isn't fixed. You can see, at line 994, that the return code rc is
ignored. The problem I face is that the ODBC driver doesn't support SQL_DESC_OCTET_LENGTH. The
ODBC driver rightfully returns an error code when PHP queries that attribute. As PHP doesn't
check the return code it continues with the uninitialized displaysize and tries to emalloc a memory
block with a size of whatever happen to be in displaysize. You can see the result in my initial
report.

You should have a look at the patch I supplied. It has been included in Debian and, so far, it works
fine.

------------------------------------------------------------------------
[2015-04-11 16:46:06] cmb@php.net

I assume the actual reason for the misbehavior is bug #68087, which
has already been fixed in 5.5.19 and 5.6.3, but will not be fixed
for PHP 5.4.

Can you please confirm that?

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=68350


--
Edit this bug report at https://bugs.php.net/bug.php?id=68350&edit=1


Thread (10 messages)

« previous php.bugs (#192170) next »