Bug #67465 [Ver->Csd]: NULL Pointer dereference in odbc_handle_preparer

From: Date: Mon, 28 Sep 2020 21:00:35 +0000
Subject: Bug #67465 [Ver->Csd]: NULL Pointer dereference in odbc_handle_preparer
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-229254@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=67465&edit=1 ID: 67465 Updated by: cmb@php.net Reported by: martin dot koegler at brz dot gv dot at Summary: NULL Pointer dereference in odbc_handle_preparer -Status: Verified +Status: Closed Type: Bug Package: PDO ODBC Operating System: any PHP Version: 5.5.13 Assigned To: cmb Block user comment: N Private report: N New Comment: Automatic comment on behalf of cmbecker69@gmx.de Revision: http://git.php.net/?p=php-src.git;a=commit;h=6acfb79276809d70bafe91a45267c8a307ca900d Log: Fix #67465: NULL Pointer dereference in odbc_handle_preparer Previous Comments: ------------------------------------------------------------------------ [2020-09-28 15:12:22] cmb@php.net The following pull request has been associated: Patch Name: Fix #67465: NULL Pointer dereference in odbc_handle_preparer On GitHub: https://github.com/php/php-src/pull/6225 Patch: https://github.com/php/php-src/pull/6225.patch ------------------------------------------------------------------------ [2014-06-17 16:55:46] martin dot koegler at brz dot gv dot at Description: ------------ If SQLSetStmtAttr fails in odbc_handle_preparer (file odbc_driver.c), pdo_odbc_stmt_error is called. At this time, stmt->driver_data is still NULL. pdo_odbc_error then tries to store the error data to einfo of the not present stmt->driver_data => SIGSEGV. Second issue is, that caller of odbc_handle_preparer expects the error in the error structure of the db connection handle. Possible fix: --- ext/pdo_odbc/odbc_driver.c.orig 2014-06-17 18:18:14.529836822 +0200 +++ ext/pdo_odbc/odbc_driver.c 2014-06-17 18:41:55.907685218 +0200 @@ -67,7 +67,7 @@ pdo_odbc_stmt *S = NULL; pdo_error_type *pdo_err = &dbh->error_code; - if (stmt) { + if (stmt && stmt->driver_data) { S = (pdo_odbc_stmt*)stmt->driver_data; einfo = &S->einfo; @@ -185,7 +185,7 @@ if (cursor_type != PDO_CURSOR_FWDONLY) { rc = SQLSetStmtAttr(S->stmt, SQL_ATTR_CURSOR_SCROLLABLE, (void*)SQL_SCROLLABLE, 0); if (rc != SQL_SUCCESS && rc != SQL_SUCCESS_WITH_INFO) { - pdo_odbc_stmt_error("SQLSetStmtAttr: SQL_ATTR_CURSOR_SCROLLABLE"); + pdo_odbc_error(stmt->dbh, stmt, S->stmt, "SQLSetStmtAttr: SQL_ATTR_CURSOR_SCROLLABLE", __FILE__, __LINE__ TSRMLS_CC); SQLFreeHandle(SQL_HANDLE_STMT, S->stmt); if (nsql) { efree(nsql); ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=67465&edit=1

« previous php.bugs (#229254) next »