Bug #70032 [Asn]: make_http_soap_request calls zend_hash_get_current_key_ex(,,,NULL)
| From: | laruence@php.net | Date: | Thu, 09 Jul 2015 08:41:12 +0000 |
| Subject: | Bug #70032 [Asn]: make_http_soap_request calls zend_hash_get_current_key_ex(,,,NULL) | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-194243@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=70032&edit=1
ID: 70032
Updated by: laruence@php.net
Reported by: turchanov at farpost dot com
Summary: make_http_soap_request calls
zend_hash_get_current_key_ex(,,,NULL)
Status: Assigned
Type: Bug
Package: SOAP related
Operating System: Linux
PHP Version: 7.0.0alpha2
Assigned To: laruence
Block user comment: N
Private report: N
New Comment:
this should be fixed by using zend_hash_get_current_key instead..
thanks
Previous Comments:
------------------------------------------------------------------------
[2015-07-09 08:18:04] turchanov at farpost dot com
> Turchanov at farpost dot com, if you got an example/test case, could you please attach it to
> this bug report?
I doubt it mostly due to the necessity to have a separate SOAP server which uses(!) cookies as the
code in question at php_http.c:817 appends client cookies to HTTP request headers (... and fails
with the segfault).
------------------------------------------------------------------------
[2015-07-09 07:36:40] kalle@php.net
Xinchen, I'm assigning this to you, I'm not sure whether or not you want the internal hash
API to change or the usage of zend_hash_get_current_key_ex().
Turchanov at farpost dot com, if you got an example/test case, could you please attach it to this
bug report?
------------------------------------------------------------------------
[2015-07-09 06:50:18] turchanov at farpost dot com
Description:
------------
make_http_soap_request at php_http.c:817 makes a call
...
zend_hash_get_current_key_ex(Z_ARRVAL_P(cookies), &key, NULL, NULL);
...
But implementation of zend_hash_get_current_key_ex does dereferencing of 'pos' parameter
without checking it is not NULL:
ZEND_API int ZEND_FASTCALL zend_hash_get_current_key_ex(const HashTable *ht, zend_string
**str_index, zend_ulong *num_index, HashPosition *pos)
{
uint32_t idx = *pos; /* !!!!!! */
in php 5.6.x the same function does checking:
ZEND_API int zend_hash_get_current_key_ex(const HashTable *ht, char **str_index, uint *str_length,
ulong *num_index, zend_bool duplicate, HashPosition *pos)
{
Bucket *p;
p = pos ? (*pos) : ht->pInternalPointer;
Actual result:
--------------
Program terminated with signal 11, Segmentation fault.
#0 zend_hash_get_current_key_ex (ht=0x7f908a4a04d0, str_index=0x7fff0b8eee40, num_index=0x0,
pos=0x0) at /usr/src/debug/php-src-master/Zend/zend_hash.c:2032
2032 uint32_t idx = *pos;
(gdb) bt
#0 zend_hash_get_current_key_ex (ht=0x7f908a4a04d0, str_index=0x7fff0b8eee40, num_index=0x0,
pos=0x0) at /usr/src/debug/php-src-master/Zend/zend_hash.c:2032
#1 0x00000000006fb368 in make_http_soap_request (this_ptr=<value optimized out>,
buf=0x7f908a3f9318 "<?xml version=\"1.0\""..., buf_size=<value
optimized out>, location=<value optimized out>,
soapaction=<value optimized out>, soap_version=1, return_value=0x7f909d815050) at
/usr/src/debug/php-src-master/ext/soap/php_http.c:817
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=70032&edit=1