cvs: php4 /ext/pgsql pgsql.c
| From: | Yasuo Ohgaki | Date: | Mon, 20 May 2002 01:40:23 +0000 |
| Subject: | cvs: php4 /ext/pgsql pgsql.c | ||
| Groups: | php.cvs | ||
| Request: | Send a blank email to php-cvs+get-12011@lists.php.net to get a copy of this message | ||
yohgaki Sun May 19 21:40:23 2002 EDT
Modified files:
/php4/ext/pgsql pgsql.c
Log:
Fixed possible pg_lo_write() overflow and make it more fail safe.
Index: php4/ext/pgsql/pgsql.c
diff -u php4/ext/pgsql/pgsql.c:1.200 php4/ext/pgsql/pgsql.c:1.201
--- php4/ext/pgsql/pgsql.c:1.200 Sun May 19 21:02:29 2002
+++ php4/ext/pgsql/pgsql.c Sun May 19 21:40:22 2002
@@ -19,7 +19,7 @@
+----------------------------------------------------------------------+
*/
-/* $Id: pgsql.c,v 1.200 2002/05/20 01:02:29 yohgaki Exp $ */
+/* $Id: pgsql.c,v 1.201 2002/05/20 01:40:22 yohgaki Exp $ */
#include <stdlib.h>
@@ -1904,6 +1904,16 @@
if (argc > 2) {
convert_to_long_ex(z_len);
+ if (Z_LVAL_PP(z_len) > Z_STRLEN_PP(str)) {
+ php_error(E_WARNING, "%s() cannot write more than buffer size %d. Tried to wtite %d",
+ get_active_function_name(TSRMLS_C), Z_LVAL_PP(str), Z_LVAL_PP(z_len));
+ RETURN_FALSE;
+ }
+ if (Z_LVAL_PP(z_len) < 0) {
+ php_error(E_WARNING, "%s() buffer size must be larger than 0. %d specified for buffer
size.",
+ get_active_function_name(TSRMLS_C), Z_LVAL_PP(str), Z_LVAL_PP(z_len));
+ RETURN_FALSE;
+ }
len = Z_LVAL_PP(z_len);
}
else {
@@ -1925,7 +1935,7 @@
PHP_FUNCTION(pg_lo_read_all)
{
zval **pgsql_id;
- int i, tbytes;
+ int tbytes;
volatile int nbytes;
char buf[PGSQL_LO_READ_BUF_SIZE];
pgLofp *pgsql;