Bug #67465 [Opn->Ver]: NULL Pointer dereference in odbc_handle_preparer

From: Date: Mon, 28 Sep 2020 15:07:10 +0000
Subject: Bug #67465 [Opn->Ver]: NULL Pointer dereference in odbc_handle_preparer
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-229248@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=67465&edit=1

 ID:                 67465
 Updated by:         cmb@php.net
 Reported by:        martin dot koegler at brz dot gv dot at
 Summary:            NULL Pointer dereference in odbc_handle_preparer
-Status:             Open
+Status:             Verified
 Type:               Bug
 Package:            PDO ODBC
 Operating System:   any
 PHP Version:        5.5.13
-Assigned To:        
+Assigned To:        cmb
 Block user comment: N
 Private report:     N



Previous Comments:
------------------------------------------------------------------------
[2014-06-17 16:55:46] martin dot koegler at brz dot gv dot at

Description:
------------
If SQLSetStmtAttr fails in odbc_handle_preparer (file odbc_driver.c), pdo_odbc_stmt_error is called.
At this time, stmt->driver_data is still NULL.

pdo_odbc_error then tries to store the error data to einfo of the not present stmt->driver_data
=> SIGSEGV.

Second issue is, that caller of odbc_handle_preparer expects the error in the error structure of the
db connection handle.

Possible fix:
--- ext/pdo_odbc/odbc_driver.c.orig     2014-06-17 18:18:14.529836822 +0200
+++ ext/pdo_odbc/odbc_driver.c  2014-06-17 18:41:55.907685218 +0200
@@ -67,7 +67,7 @@
        pdo_odbc_stmt *S = NULL;
        pdo_error_type *pdo_err = &dbh->error_code;

-       if (stmt) {
+       if (stmt && stmt->driver_data) {
                S = (pdo_odbc_stmt*)stmt->driver_data;

                einfo = &S->einfo;
@@ -185,7 +185,7 @@
        if (cursor_type != PDO_CURSOR_FWDONLY) {
                rc = SQLSetStmtAttr(S->stmt, SQL_ATTR_CURSOR_SCROLLABLE, (void*)SQL_SCROLLABLE,
0);
                if (rc != SQL_SUCCESS && rc != SQL_SUCCESS_WITH_INFO) {
-                       pdo_odbc_stmt_error("SQLSetStmtAttr: SQL_ATTR_CURSOR_SCROLLABLE");
+                       pdo_odbc_error(stmt->dbh, stmt, S->stmt, "SQLSetStmtAttr:
SQL_ATTR_CURSOR_SCROLLABLE", __FILE__, __LINE__ TSRMLS_CC);
                        SQLFreeHandle(SQL_HANDLE_STMT, S->stmt);
                        if (nsql) {
                                efree(nsql);





------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=67465&edit=1


Thread (4 messages)

« previous php.bugs (#229248) next »