#23162 [Ana]: user_error() crashs if $error_msg > 1024 bytes
| From: | moriyoshi@php.net | Date: | Fri, 02 May 2003 22:19:29 +0000 |
| Subject: | #23162 [Ana]: user_error() crashs if $error_msg > 1024 bytes | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-38962@lists.php.net to get a copy of this message | ||
ID: 23162
Updated by: moriyoshi@php.net
Reported By: dimon at postmark dot net
Status: Analyzed
Bug Type: Scripting Engine problem
Operating System: Windows 2000 Server (only!)
PHP Version: 4.3.2-RC
New Comment:
(where valid vsnprintf() implementation is missing.)
case (a) and case (b): MS libc's vsnprintf() returns -1 if the
resulting string has exceeded the limit length specified in the second
parameter. This may cause segfaults in some cases like those.
case (c): jay's suggestion looks like a valid fix to me since that's
essentially a referenced variable.
Here's the patch. Could anyone with ZE karma apply this one please?
Index: Zend/zend.c
===================================================================
RCS file: /repository/Zend/zend.c,v
retrieving revision 1.162.2.2
diff -u -r1.162.2.2 zend.c
--- Zend/zend.c 31 Dec 2002 16:22:56 -0000 1.162.2.2
+++ Zend/zend.c 2 May 2003 22:17:45 -0000
@@ -754,11 +754,14 @@
#ifdef HAVE_VSNPRINTF
z_error_message->value.str.len =
vsnprintf(z_error_message->value.str.val, ZEND_ERROR_BUFFER_SIZE,
format, args);
- if (z_error_message->value.str.len > ZEND_ERROR_BUFFER_SIZE-1) {
+ if (z_error_message->value.str.len < 0 ||
z_error_message->value.str.len > ZEND_ERROR_BUFFER_SIZE-1) {
+ z_error_message->value.str.val[ZEND_ERROR_BUFFER_SIZE-1] = '\0';
z_error_message->value.str.len = ZEND_ERROR_BUFFER_SIZE-1;
}
#else
- strncpy(z_error_message->value.str.val, format,
ZEND_ERROR_BUFFER_SIZE);
+ strncpy(z_error_message->value.str.val, va_arg(format, char *),
ZEND_ERROR_BUFFER_SIZE);
+ z_error_message->value.str.val[ZEND_ERROR_BUFFER_SIZE - 1] = '\0';
+ z_error_message->value.str.len =
strlen(z_error_message->value.str.val);
/* This is risky... */
/* z_error_message->value.str.len =
vsprintf(z_error_message->value.str.val, format, args); */
#endif
@@ -778,7 +781,8 @@
z_context->value.ht = EG(active_symbol_table);
z_context->type = IS_ARRAY;
- ZVAL_ADDREF(z_context); /* we don't want this one to be freed */
+ z_context->is_ref = 1;
+ z_context->refcount = 2; /* we don't want this one to be freed */
params = (zval ***) emalloc(sizeof(zval **)*5);
params[0] = &z_error_type;
Previous Comments:
------------------------------------------------------------------------
[2003-05-02 16:57:57] helly@php.net
If vsnprintf is the cause then it should be easy to expand the
<whatever>printf broken tests what would result in using the internal
one.
------------------------------------------------------------------------
[2003-05-02 16:10:21] moriyoshi@php.net
Segfault could happen on platforms where vsnprintf() is missing.
------------------------------------------------------------------------
[2003-05-02 06:30:12] sniper@php.net
Does not crash under Linux.
------------------------------------------------------------------------
[2003-04-14 15:27:20] jay@php.net
I have no idea if this hurts anything (hasn't given me any
trouble), but adding "z_context->is_ref = 1;" to zend.c
before calling call_user_function_ex() in zend_error()
seems to fix the "$context passed by reference" segfault.
Not being much of a ZE engine hacker, I don't know if that
makes things better or worse.
J
------------------------------------------------------------------------
[2003-04-14 03:47:06] dimon at postmark dot net
In Version 4.3.2-RC Apr 14 2003 02:12:05
bug still exists.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
http://bugs.php.net/23162
--
Edit this bug report at http://bugs.php.net/?id=23162&edit=1