cvs: php4 /ext/pgsql pgsql.c

From: Date: Mon, 20 May 2002 01:40:23 +0000
Subject: cvs: php4 /ext/pgsql pgsql.c
Groups: php.cvs 
Request: Send a blank email to php-cvs+get-12011@lists.php.net to get a copy of this message
yohgaki Sun May 19 21:40:23 2002 EDT Modified files: /php4/ext/pgsql pgsql.c Log: Fixed possible pg_lo_write() overflow and make it more fail safe. Index: php4/ext/pgsql/pgsql.c diff -u php4/ext/pgsql/pgsql.c:1.200 php4/ext/pgsql/pgsql.c:1.201 --- php4/ext/pgsql/pgsql.c:1.200 Sun May 19 21:02:29 2002 +++ php4/ext/pgsql/pgsql.c Sun May 19 21:40:22 2002 @@ -19,7 +19,7 @@ +----------------------------------------------------------------------+ */ -/* $Id: pgsql.c,v 1.200 2002/05/20 01:02:29 yohgaki Exp $ */ +/* $Id: pgsql.c,v 1.201 2002/05/20 01:40:22 yohgaki Exp $ */ #include <stdlib.h> @@ -1904,6 +1904,16 @@ if (argc > 2) { convert_to_long_ex(z_len); + if (Z_LVAL_PP(z_len) > Z_STRLEN_PP(str)) { + php_error(E_WARNING, "%s() cannot write more than buffer size %d. Tried to wtite %d", + get_active_function_name(TSRMLS_C), Z_LVAL_PP(str), Z_LVAL_PP(z_len)); + RETURN_FALSE; + } + if (Z_LVAL_PP(z_len) < 0) { + php_error(E_WARNING, "%s() buffer size must be larger than 0. %d specified for buffer size.", + get_active_function_name(TSRMLS_C), Z_LVAL_PP(str), Z_LVAL_PP(z_len)); + RETURN_FALSE; + } len = Z_LVAL_PP(z_len); } else { @@ -1925,7 +1935,7 @@ PHP_FUNCTION(pg_lo_read_all) { zval **pgsql_id; - int i, tbytes; + int tbytes; volatile int nbytes; char buf[PGSQL_LO_READ_BUF_SIZE]; pgLofp *pgsql;

« previous php.cvs (#12011) next »