#23162 [Ana->Ctl]: user_error() crashs if $error_msg > 1024 bytes
| From: | helly@php.net | Date: | Sun, 04 May 2003 16:58:31 +0000 |
| Subject: | #23162 [Ana->Ctl]: user_error() crashs if $error_msg > 1024 bytes | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-39034@lists.php.net to get a copy of this message | ||
ID: 23162
Updated by: helly@php.net
Reported By: dimon at postmark dot net
-Status: Analyzed
+Status: Critical
Bug Type: Scripting Engine problem
Operating System: Windows 2000 Server (only!)
PHP Version: 4.3.2-RC
-Assigned To: edink
+Assigned To: helly
Previous Comments:
------------------------------------------------------------------------
[2003-05-02 17:38:05] helly@php.net
[v]snprintf of MSVC is not C99 compliant which we rely on so the patch
is irrelevant and we must use our implementation fo windows.
------------------------------------------------------------------------
[2003-05-02 17:19:28] moriyoshi@php.net
(where valid vsnprintf() implementation is missing.)
case (a) and case (b): MS libc's vsnprintf() returns -1 if the
resulting string has exceeded the limit length specified in the second
parameter. This may cause segfaults in some cases like those.
case (c): jay's suggestion looks like a valid fix to me since that's
essentially a referenced variable.
Here's the patch. Could anyone with ZE karma apply this one please?
Index: Zend/zend.c
===================================================================
RCS file: /repository/Zend/zend.c,v
retrieving revision 1.162.2.2
diff -u -r1.162.2.2 zend.c
--- Zend/zend.c 31 Dec 2002 16:22:56 -0000 1.162.2.2
+++ Zend/zend.c 2 May 2003 22:17:45 -0000
@@ -754,11 +754,14 @@
#ifdef HAVE_VSNPRINTF
z_error_message->value.str.len =
vsnprintf(z_error_message->value.str.val, ZEND_ERROR_BUFFER_SIZE,
format, args);
- if (z_error_message->value.str.len > ZEND_ERROR_BUFFER_SIZE-1) {
+ if (z_error_message->value.str.len < 0 ||
z_error_message->value.str.len > ZEND_ERROR_BUFFER_SIZE-1) {
+ z_error_message->value.str.val[ZEND_ERROR_BUFFER_SIZE-1] = '\0';
z_error_message->value.str.len = ZEND_ERROR_BUFFER_SIZE-1;
}
#else
- strncpy(z_error_message->value.str.val, format,
ZEND_ERROR_BUFFER_SIZE);
+ strncpy(z_error_message->value.str.val, va_arg(format, char *),
ZEND_ERROR_BUFFER_SIZE);
+ z_error_message->value.str.val[ZEND_ERROR_BUFFER_SIZE - 1] = '\0';
+ z_error_message->value.str.len =
strlen(z_error_message->value.str.val);
/* This is risky... */
/* z_error_message->value.str.len =
vsprintf(z_error_message->value.str.val, format, args); */
#endif
@@ -778,7 +781,8 @@
z_context->value.ht = EG(active_symbol_table);
z_context->type = IS_ARRAY;
- ZVAL_ADDREF(z_context); /* we don't want this one to be freed */
+ z_context->is_ref = 1;
+ z_context->refcount = 2; /* we don't want this one to be freed */
params = (zval ***) emalloc(sizeof(zval **)*5);
params[0] = &z_error_type;
------------------------------------------------------------------------
[2003-05-02 16:57:57] helly@php.net
If vsnprintf is the cause then it should be easy to expand the
<whatever>printf broken tests what would result in using the internal
one.
------------------------------------------------------------------------
[2003-05-02 16:10:21] moriyoshi@php.net
Segfault could happen on platforms where vsnprintf() is missing.
------------------------------------------------------------------------
[2003-05-02 06:30:12] sniper@php.net
Does not crash under Linux.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
http://bugs.php.net/23162
--
Edit this bug report at http://bugs.php.net/?id=23162&edit=1