Bug #54169 [Com]: Garbage Pointers returned for (n)varchar(max) columns (SQL Server)
| From: | deankearney at gmail dot com | Date: | Thu, 17 Dec 2015 20:15:35 +0000 |
| Subject: | Bug #54169 [Com]: Garbage Pointers returned for (n)varchar(max) columns (SQL Server) | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-197977@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=54169&edit=1
ID: 54169
Comment by: deankearney at gmail dot com
Reported by: auroraeosrose@php.net
Summary: Garbage Pointers returned for (n)varchar(max)
columns (SQL Server)
Status: Assigned
Type: Bug
Package: PDO ODBC
Operating System: Any
PHP Version: Irrelevant
Assigned To: auroraeosrose
Block user comment: N
Private report: N
New Comment:
This bug still exists in php7. The fix works. Can we get this merged in?
Previous Comments:
------------------------------------------------------------------------
[2015-06-05 17:56:20] cmb@php.net
Related To: Bug #44278
------------------------------------------------------------------------
[2015-05-27 00:05:07] jlongo at kastle dot com
@trapper - it isn't necessarily a "problem" in ODBC... it is a change in behavior for
Microsoft's ODBC Driver 11 implementation. As of ODBC Driver 11, they are returning the length
as 0 for max fields. They used to return a very large number for the column size, such as 2147483647
when running on a 32 bit platform, when using varchar(max) fields in prior versions of their driver.
As an effect, the pure odbc extension will also need this kind of update to work with
Microsoft's ODBC Driver 11 and max fields.
------------------------------------------------------------------------
[2015-05-26 23:53:07] jlongo at kastle dot com
Hey guys... this bug has been sitting for far too long IMO. This needs to be identified as a
security issue. The garbage pointers that I get back when testing this flaw more times than not
will contain the contents of the script source that I am running. I have verified that the patch
that was submitted works, so really it should just be a matter of folks merging it into the
supported PHP versions for the next patch release.
------------------------------------------------------------------------
[2015-02-05 18:38:52] trapper at coremr dot com
This bug is still in the latest version of PHP at this moment (5.6). It affects all the versions of
the SQL Server Native Client ODBC drivers and makes them unfeasible to use because of it.
As its a problem inside ODBC, it is currently affecting both raw odbc_* functions as well as any PDO
connections.
------------------------------------------------------------------------
[2013-01-28 16:16:20] a dot schilder at gmx dot de
This bug is really evil and should be treated as a security issue.
In one case I got the content of a previously loaded PHP file instead of the requested field data,
so it's possible that the content of sensitive files is returned and shown.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=54169
--
Edit this bug report at https://bugs.php.net/bug.php?id=54169&edit=1