Bug #70862 [Csd]: Several functions do not check return code of php_stream_copy_to_mem()

From: Date: Thu, 05 Nov 2015 21:51:11 +0000
Subject: Bug #70862 [Csd]: Several functions do not check return code of php_stream_copy_to_mem()
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-197062@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70862&edit=1

 ID:                 70862
 Updated by:         ab@php.net
 Reported by:        fabian at tag1consulting dot com
 Summary:            Several functions do not check return code of
                     php_stream_copy_to_mem()
 Status:             Closed
 Type:               Bug
 Package:            Streams related
 Operating System:   Linux / Ubuntu
 PHP Version:        7.0Git-2015-11-05 (Git)
 Assigned To:        ab
 Block user comment: N
 Private report:     N

 New Comment:

All the vulnerable places are covered now, multiple revisions :)


Previous Comments:
------------------------------------------------------------------------
[2015-11-05 15:20:25] fabian at tag1consulting dot com

Description:
------------
Follow-up to https://bugs.php.net/bug.php?id=70861 which had the
same problem.

./ext/mbstring/mb_gpc.c
./ext/pdo_firebird/firebird_statement.c
./ext/pdo_mysql/mysql_statement.c
./ext/pdo_sqlite/sqlite_statement.c
./ext/sqlite3/sqlite3.c
./ext/standard/image.c

all have code similar to:

  ZVAL_STR(parameter, php_stream_copy_to_mem(stm, PHP_STREAM_COPY_ALL, 0));

in various variations.

However php_stream_copy_to_mem() can return NULL, which will make this code fail under certain
circumstances.

./ext/pdo/pdo_stmt.c has probably the best code for the problem to solve in a generic way:

                                        buf = php_stream_copy_to_mem((php_stream*)value,
PHP_STREAM_COPY_ALL, 0);
                                        if (buf == NULL) {
                                                ZVAL_EMPTY_STRING(dest);
                                        } else {
                                                ZVAL_STR(dest, buf);
                                        }

and this likely should be made into a macro:

ZVAL_STR_OR_EMPTY(dest, buf, stream);

Expected result:
----------------
All functions should check the return value of php_stream_copy_to_mem()

Actual result:
--------------
Some function do not yet check the return value. This could lead to bugs.


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=70862&edit=1


Thread (3 messages)

« previous php.bugs (#197062) next »