Bug #71753 [NEW]: Multiple (possible) mistakes in PHP "standard" extension code
| From: | temp at temp dot ru | Date: | Wed, 09 Mar 2016 12:09:04 +0000 |
| Subject: | Bug #71753 [NEW]: Multiple (possible) mistakes in PHP "standard" extension code | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-199695@lists.php.net to get a copy of this message | ||
From: temp at temp dot ru
Operating system:
PHP version: 7.0.4
Package: *General Issues
Bug Type: Bug
Bug description:Multiple (possible) mistakes in PHP "standard" extension code
Description:
------------
There are several possible mistakes in "standard" PHP extension code.
1. flock_compat.c, php_flock function:
HANDLE hdl = (HANDLE) _get_osfhandle(fd);
DWORD low = 1, high = 0;
OVERLAPPED offset =
{0, 0, 0, 0, NULL};
DWORD err;
if (hdl < 0) { // <-- Comparing pointer < 0. Pointer value can't be less
than zero. Correct comparison: hdl == INVALID_HANDLE_VALUE
_set_errno(EBADF);
return -1; /* error in file descriptor */
}
2. filters.c, php_conv_qprint_encode_convert function, possible zero
pointer dereferencing:
c = NEXT_CHAR(ps, icnt, lb_ptr, lb_cnt, inst->lbchars); // <-- Access to
inst->lbchars[lb_ptr] inside the macro
if (!(opts & PHP_CONV_QPRINT_OPT_BINARY) &&
(trail_ws == 0) &&
(c == '\t' || c == ' ')) {
if (line_ccnt < 2 && inst->lbchars != NULL) { // <-- Later check if
inst->lbchars is not NULL
3. http_fopen_wrapper.c, php_stream_url_wrap_http_ex function, possible
zero pointer dereferencing:
ua = emalloc(ua_len + 1);
if ((ua_len = slprintf(ua, ua_len, _UA_HEADER, ua_str)) > 0) { // <--
Access to ua
ua[ua_len] = 0;
php_stream_write(stream, ua, ua_len);
} else {
php_error_docref(NULL, E_WARNING, "Cannot construct User-agent
header");
}
if (ua) { // <-- Later check if ua is not NULL
efree(ua);
}
4. uuencode.c, php_uudecode function:
assert(p >= ZSTR_VAL(dest));
if ((len = total_len > (size_t)(p - ZSTR_VAL(dest)))) { // <-- Possible
absence of brackets: this expression should be if(((len = total_len) >
...))
5. var.c, php_var_serialize_intern function:
zend_class_entry *ce = Z_OBJCE_P(struc);
if (ce->serialize != NULL) { // <-- Access to ce->serialize
...
if (ce && ce != PHP_IC_ENTRY &&
zend_hash_str_exists(&ce->function_table, "__sleep",
sizeof("__sleep")-1)) { // <-- Later check if ce is not NULL
6. var.c, php_var_serialize_intern function (again):
if (incomplete_class && strcmp(ZSTR_VAL(key), MAGIC_MEMBER) == 0) { //
<-- Access to key->val
continue;
}
if (!key) { // <-- Later check if key is not NULL
php_var_serialize_long(buf, index);
} else {
php_var_serialize_string(buf, ZSTR_VAL(key), ZSTR_LEN(key));
}
--
Edit bug report at https://bugs.php.net/bug.php?id=71753&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=71753&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=71753&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=71753&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=71753&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=71753&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=71753&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=71753&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=71753&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=71753&r=support
Expected behavior: https://bugs.php.net/fix.php?id=71753&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=71753&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=71753&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=71753&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=71753&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=71753&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=71753&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=71753&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=71753&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=71753&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=71753&r=mysqlcfg