#26753 [Fbk->Opn]: zend_fetch_list_dtor_id() doesn't check NULL strings

From: Date: Thu, 29 Jan 2004 18:27:48 +0000
Subject: #26753 [Fbk->Opn]: zend_fetch_list_dtor_id() doesn't check NULL strings
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-54141@lists.php.net to get a copy of this message
ID: 26753 User updated by: Markus dot Lidel at shadowconnect dot com Reported By: Markus dot Lidel at shadowconnect dot com -Status: Feedback +Status: Open Bug Type: Reproducible crash Operating System: Linux PHP Version: 4CVS, 5CVS New Comment: Hi... i have two modules. One uses the other. So i use the function to get the id for the objects of the other module. Bye... Previous Comments: ------------------------------------------------------------------------ [2004-01-29 11:44:22] sniper@php.net Why do you use it? ------------------------------------------------------------------------ [2003-12-31 08:11:22] Markus dot Lidel at shadowconnect dot com BTW, found the bug in php4-200312311230 and in php5-200312311230. ------------------------------------------------------------------------ [2003-12-31 08:07:45] Markus dot Lidel at shadowconnect dot com Description: ------------ If you use the zend_fetch_list_dtor_id function, and you have for example loaded the "crack" extension (which registers a destructor using the function register_list_destructors()), php crashes. The source of the problem is this line: if (strcmp(type_name, lde->type_name) == 0) { The register_list_destructors() set lde->type_name to NULL. If you replace the code with if (lde->type_name && (strcmp(type_name, lde->type_name) == 0)) { the function works fine. Reproduce code: --------------- int id = zend_fetch_list_dtor_id function("foo"); ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=26753&edit=1

« previous php.bugs (#54141) next »