#23402 [Fbk->Opn]: mssql_bind : Unhandled exception

From: Date: Wed, 30 Apr 2003 15:49:30 +0000
Subject: #23402 [Fbk->Opn]: mssql_bind : Unhandled exception
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-38839@lists.php.net to get a copy of this message
 ID:               23402
 User updated by:  Alla <svbevno at umailrusp dot am>
 Reported By:      Alla <svbevno at umailrusp dot am>
-Status:           Feedback
+Status:           Open
 Bug Type:         MSSQL related
 Operating System: W2k
 PHP Version:      4.3.2RC2
 New Comment:

phpinfo()
Build Date         Apr 26 2003 18:46:51  
Server             API  CGI/FastCGI  
PHP API            20020918  
PHP Extension      20020429  
Zend Extension     20021010  
Debug Build        no  
Thread Safety      enabled  
Registered PHP     Streams  php, http, ftp, compress.zlib


Previous Comments:
------------------------------------------------------------------------

[2003-04-30 06:00:34] sniper@php.net

What does phpinfo() say about php version?


------------------------------------------------------------------------

[2003-04-29 05:38:17] Alla <svbevno at umailrusp dot am>

BUG: mssql_bind() causes memory access violation.

The second call to mssql_bind (without mssql_init) leads to memory
access violation: 'memory can not be written'.
mssql_init()
mssql_bind()
mssql_execute()
mssql_bind()     // !!!!!!! CRASH !!!!!!!
mssql_execute()

==========================================================
LOCATION:

Module             : php4ts.dll, 
File               : php_mssql.c
Line               : ! CRASH ! (see below)

Cause              : zend_hash_add(..) return NULL for the output
variable 'bindp', and this is not checked in the code

Possible Fix       : add: if( NULL == bindp ) RETURN_FALSE;

Existing code source:

PHP_FUNCTION(mssql_bind)
{
  ........
  memset((void*)&bind,0,sizeof(mssql_bind));

  zend_hash_add( 
     statement->binds,
     Z_STRVAL_PP(param_name),
     Z_STRLEN_PP(param_name),
     &bind,sizeof(mssql_bind),
     (void **)&bindp );         // bindp == NULL here!

  bindp->zval = *var;           // !!!!!! CRASH !!!!!!!

  zval_add_ref(var);

  if(.....) 
  {
    ......
  }

  RETURN_TRUE;
}

------------------------------------------------------------------------


-- 
Edit this bug report at http://bugs.php.net/?id=23402&edit=1



Thread (6 messages)

« previous php.bugs (#38839) next »