Bug #80366 [Ver->Csd]: Potential issue in ext/standard/iptc.c: Return Value Not Checked

From: Date: Tue, 24 Nov 2020 12:11:36 +0000
Subject: Bug #80366 [Ver->Csd]: Potential issue in ext/standard/iptc.c: Return Value Not Checked
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-230574@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80366&edit=1 ID: 80366 Updated by: cmb@php.net Reported by: sagpant at microsoft dot com Summary: Potential issue in ext/standard/iptc.c: Return Value Not Checked -Status: Verified +Status: Closed Type: Bug Package: GetImageSize related PHP Version: 7.4.12 Assigned To: cmb Block user comment: N Private report: N New Comment: Automatic comment on behalf of cmbecker69@gmx.de Revision: http://git.php.net/?p=php-src.git;a=commit;h=5f9c82d514980f96e5e88f6c2633571ce31b57a7 Log: Fix #80366: Return Value of zend_fstat() not Checked Previous Comments: ------------------------------------------------------------------------ [2020-11-17 13:49:37] cmb@php.net The following pull request has been associated: Patch Name: Fix #80366: Return Value of zend_fstat() not Checked On GitHub: https://github.com/php/php-src/pull/6432 Patch: https://github.com/php/php-src/pull/6432.patch ------------------------------------------------------------------------ [2020-11-17 13:48:34] cmb@php.net Thanks for reporting this issue and providing a patch. I think we have to bail out of the function if this zend_fstat() call fails, though. ------------------------------------------------------------------------ [2020-11-13 19:32:05] sagpant at microsoft dot com The following patch has been added/updated: Patch Name: iptc_fix.patch Revision: 1605295925 URL: https://bugs.php.net/patch-display.php?bug=80366&patch=iptc_fix.patch&revision=1605295925 ------------------------------------------------------------------------ [2020-11-13 19:23:24] levim@php.net Nits on the patch: I prefer == 0 over != 1. The nested if is unnecessary; combine it with the surrounding if. ------------------------------------------------------------------------ [2020-11-13 19:12:54] sagpant at microsoft dot com Description: ------------ In this codebase, you often check the return value of the implicated function when calling it, but at this instance, it appears that you didn’t. Using a consistent return value checking and/or error handling approach can improve code robustness and readability. File: PHP-7.4.12/ext/standard/iptc.c Line Number: 220 Function: zend_fstat Correct reference usage found in main/streams/plain_wrapper.c line: 160 Test script: --------------- Analyzer points out inconsistencies in the code. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=80366&edit=1

« previous php.bugs (#230574) next »