Bug #16811 Updated: Crash in shell_exec when popen fails (fix included)
| From: | sniper@php.net | Date: | Thu, 25 Apr 2002 14:04:22 +0000 |
| Subject: | Bug #16811 Updated: Crash in shell_exec when popen fails (fix included) | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-5966@lists.php.net to get a copy of this message | ||
ID: 16811
Updated by: sniper@php.net
Reported By: swbrown@ucsd.edu
Status: Closed
Bug Type: Reproducible crash
Operating System: any
PHP Version: 4.2.0
New Comment:
And the fix will be in PHP 4.2.1
Previous Comments:
------------------------------------------------------------------------
[2002-04-25 02:45:22] derick@php.net
This bug has been fixed in CVS.
------------------------------------------------------------------------
[2002-04-24 19:36:21] swbrown@ucsd.edu
(This web form will probably eat the diff, so you can also get it here:
http://www.cs.ucsd.edu/~sbrown/php-shell_exec-fix.diff)
If PHP is resource-starved and can't popen, the shell_exec function
detects the error but forgets to return, resulting in a NULL (FILE *)
being passed to fread on line 466 of exec.c (PHP 4.2.0) which causes a
crash. This patch adds the missing RETURN_FALSE.
Steven Brown <swbrown@ucsd.edu>
--- php-4.2.0/ext/standard/exec.c Tue Dec 11 07:30:29 2001
+++ php-4.2.0-fixed/ext/standard/exec.c Wed Apr 24 15:39:56 2002
@@ -459,6 +459,7 @@
if ((in=VCWD_POPEN(Z_STRVAL_PP(cmd), "r"))==NULL) {
#endif
php_error(E_WARNING, "Unable to execute '%s'", Z_STRVAL_PP(cmd));
+ RETURN_FALSE;
}
allocated_space = EXEC_INPUT_BUF;
ret = (char *) emalloc(allocated_space);
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=16811&edit=1