Bug #80366 [Opn->Ver]: Potential issue in ext/standard/iptc.c: Return Value Not Checked
| From: | cmb@php.net | Date: | Tue, 17 Nov 2020 13:48:34 +0000 |
| Subject: | Bug #80366 [Opn->Ver]: Potential issue in ext/standard/iptc.c: Return Value Not Checked | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-230409@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=80366&edit=1
ID: 80366
Updated by: cmb@php.net
Reported by: sagpant at microsoft dot com
Summary: Potential issue in ext/standard/iptc.c: Return Value
Not Checked
-Status: Open
+Status: Verified
Type: Bug
-Package: *General Issues
+Package: GetImageSize related
PHP Version: 7.4.12
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Thanks for reporting this issue and providing a patch. I think we
have to bail out of the function if this zend_fstat() call fails,
though.
Previous Comments:
------------------------------------------------------------------------
[2020-11-13 19:32:05] sagpant at microsoft dot com
The following patch has been added/updated:
Patch Name: iptc_fix.patch
Revision: 1605295925
URL: https://bugs.php.net/patch-display.php?bug=80366&patch=iptc_fix.patch&revision=1605295925
------------------------------------------------------------------------
[2020-11-13 19:23:24] levim@php.net
Nits on the patch:
I prefer
== 0 over != 1.
The nested if is unnecessary; combine it with the surrounding if.
------------------------------------------------------------------------
[2020-11-13 19:12:54] sagpant at microsoft dot com
Description:
------------
In this codebase, you often check the return value of the implicated function when calling it, but
at this instance, it appears that you didnât. Using a consistent return value checking and/or
error handling approach can improve code robustness and readability.
File: PHP-7.4.12/ext/standard/iptc.c
Line Number: 220
Function: zend_fstat
Correct reference usage found in main/streams/plain_wrapper.c line: 160
Test script:
---------------
Analyzer points out inconsistencies in the code.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=80366&edit=1