Bug #54169 [Opn->Csd]: Garbage Pointers returned for (n)varchar(max) columns (SQL Server)

From: Date: Tue, 04 Feb 2020 08:57:26 +0000
Subject: Bug #54169 [Opn->Csd]: Garbage Pointers returned for (n)varchar(max) columns (SQL Server)
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-225342@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=54169&edit=1 ID: 54169 Updated by: cmb@php.net Reported by: auroraeosrose@php.net Summary: Garbage Pointers returned for (n)varchar(max) columns (SQL Server) -Status: Open +Status: Closed Type: Bug Package: PDO ODBC Operating System: Any PHP Version: Irrelevant -Assigned To: +Assigned To: cmb Block user comment: N Private report: N Previous Comments: ------------------------------------------------------------------------ [2020-02-01 17:01:49] cmb@php.net Since issuing a CVE now would not make sense, I'm re-categorizing as bug. ------------------------------------------------------------------------ [2016-07-28 16:11:32] cmb@php.net This issue has been fixed as of PHP 5.6.23 and PHP 7.0.6 with commit <https://github.com/php/php-src/commit/4df5f79> (if it has been fixed[1]), but it is neither mentioned in NEWS nor the changelog. Anyway, I'm pretty sure that this is the same issue that has been reported as bug #69975 for ODBC (but not for PDO_ODBC). As such it is a vulnerability, as already been pointed out in comments to this reports, and would require a CVE. Therefore I'm marking this as security issue (not because it would make sense to hide this report now). [1] <https://github.com/php/php-src/pull/348#issuecomment-19565798> ------------------------------------------------------------------------ [2016-07-28 15:35:33] cmb@php.net > The fix works. According to dpayne it doesn't, see <https://github.com/php/php-src/pull/348#issuecomment-19565798>. ------------------------------------------------------------------------ [2016-04-07 03:44:07] jlongo at kastle dot com no issues with the patch. Apparently PHP is happy to keep security vulnerabilities in multiple versions of their code base for years on end after a patch is submitted. someone who is an official php developer is gonna have to kick this. we have pulled the patch in and have applied it to our builds of PHP that we use with no issue except that it requires extra effort to do a custom patch and compile of source. ------------------------------------------------------------------------ [2016-04-07 02:49:32] calioptrix at gmail dot com I just spent three hours chasing down this bug. I'm using php 5.6.0 with sql server 2014. Does the proposed patch have issues? As a band-aid, I got around the issue by casting to a varchar of length 8000, the maximum length of a "regular" varchar. In this particular case, truncating the field won't be an issue. SELECT CAST(ColumnName AS VARCHAR(8000)) AS ColumnFixed FROM Table ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=54169 -- Edit this bug report at https://bugs.php.net/bug.php?id=54169&edit=1

« previous php.bugs (#225342) next »