#23162 [Ana->Ctl]: user_error() crashs if $error_msg > 1024 bytes

From: Date: Sun, 04 May 2003 16:58:31 +0000
Subject: #23162 [Ana->Ctl]: user_error() crashs if $error_msg > 1024 bytes
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-39034@lists.php.net to get a copy of this message
ID: 23162 Updated by: helly@php.net Reported By: dimon at postmark dot net -Status: Analyzed +Status: Critical Bug Type: Scripting Engine problem Operating System: Windows 2000 Server (only!) PHP Version: 4.3.2-RC -Assigned To: edink +Assigned To: helly Previous Comments: ------------------------------------------------------------------------ [2003-05-02 17:38:05] helly@php.net [v]snprintf of MSVC is not C99 compliant which we rely on so the patch is irrelevant and we must use our implementation fo windows. ------------------------------------------------------------------------ [2003-05-02 17:19:28] moriyoshi@php.net (where valid vsnprintf() implementation is missing.) case (a) and case (b): MS libc's vsnprintf() returns -1 if the resulting string has exceeded the limit length specified in the second parameter. This may cause segfaults in some cases like those. case (c): jay's suggestion looks like a valid fix to me since that's essentially a referenced variable. Here's the patch. Could anyone with ZE karma apply this one please? Index: Zend/zend.c =================================================================== RCS file: /repository/Zend/zend.c,v retrieving revision 1.162.2.2 diff -u -r1.162.2.2 zend.c --- Zend/zend.c 31 Dec 2002 16:22:56 -0000 1.162.2.2 +++ Zend/zend.c 2 May 2003 22:17:45 -0000 @@ -754,11 +754,14 @@ #ifdef HAVE_VSNPRINTF z_error_message->value.str.len = vsnprintf(z_error_message->value.str.val, ZEND_ERROR_BUFFER_SIZE, format, args); - if (z_error_message->value.str.len > ZEND_ERROR_BUFFER_SIZE-1) { + if (z_error_message->value.str.len < 0 || z_error_message->value.str.len > ZEND_ERROR_BUFFER_SIZE-1) { + z_error_message->value.str.val[ZEND_ERROR_BUFFER_SIZE-1] = '\0'; z_error_message->value.str.len = ZEND_ERROR_BUFFER_SIZE-1; } #else - strncpy(z_error_message->value.str.val, format, ZEND_ERROR_BUFFER_SIZE); + strncpy(z_error_message->value.str.val, va_arg(format, char *), ZEND_ERROR_BUFFER_SIZE); + z_error_message->value.str.val[ZEND_ERROR_BUFFER_SIZE - 1] = '\0'; + z_error_message->value.str.len = strlen(z_error_message->value.str.val); /* This is risky... */ /* z_error_message->value.str.len = vsprintf(z_error_message->value.str.val, format, args); */ #endif @@ -778,7 +781,8 @@ z_context->value.ht = EG(active_symbol_table); z_context->type = IS_ARRAY; - ZVAL_ADDREF(z_context); /* we don't want this one to be freed */ + z_context->is_ref = 1; + z_context->refcount = 2; /* we don't want this one to be freed */ params = (zval ***) emalloc(sizeof(zval **)*5); params[0] = &z_error_type; ------------------------------------------------------------------------ [2003-05-02 16:57:57] helly@php.net If vsnprintf is the cause then it should be easy to expand the <whatever>printf broken tests what would result in using the internal one. ------------------------------------------------------------------------ [2003-05-02 16:10:21] moriyoshi@php.net Segfault could happen on platforms where vsnprintf() is missing. ------------------------------------------------------------------------ [2003-05-02 06:30:12] sniper@php.net Does not crash under Linux. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at http://bugs.php.net/23162 -- Edit this bug report at http://bugs.php.net/?id=23162&edit=1

« previous php.bugs (#39034) next »