cvs: php4 /ext/standard string.c
| From: | Ilia Alshanetsky | Date: | Thu, 05 Sep 2002 14:00:30 +0000 |
| Subject: | cvs: php4 /ext/standard string.c | ||
| Groups: | php.cvs | ||
| Request: | Send a blank email to php-cvs+get-13857@lists.php.net to get a copy of this message | ||
iliaa Thu Sep 5 10:00:30 2002 EDT
Modified files:
/php4/ext/standard string.c
Log:
Fixed a buffer overflow that occurs when wordwrap is unable to calculate
the correct number of times the multi-byte break needs to be inserted into
the string.
Index: php4/ext/standard/string.c
diff -u php4/ext/standard/string.c:1.288 php4/ext/standard/string.c:1.289
--- php4/ext/standard/string.c:1.288 Thu Sep 5 07:29:31 2002
+++ php4/ext/standard/string.c Thu Sep 5 10:00:28 2002
@@ -18,7 +18,7 @@
+----------------------------------------------------------------------+
*/
-/* $Id: string.c,v 1.288 2002/09/05 11:29:31 derick Exp $ */
+/* $Id: string.c,v 1.289 2002/09/05 14:00:28 iliaa Exp $ */
/* Synced with php 3.0 revision 1.193 1999-06-16 [ssb] */
@@ -640,13 +640,14 @@
else {
/* Multiple character line break or forced cut */
if (linelength > 0) {
- newtextlen = textlen + (textlen/linelength + 1) * breakcharlen + 1;
+ /* Add extra 10% to accomodate strings with unpredicatable number of breaks */
+ newtextlen = textlen + (textlen/linelength + 1) * breakcharlen * 1.1 + 1;
}
else {
newtextlen = textlen * (breakcharlen + 1) + 1;
}
newtext = emalloc(newtextlen);
-
+
/* now keep track of the actual new text length */
newtextlen = 0;
@@ -705,6 +706,8 @@
}
newtext[newtextlen] = '\0';
+ /* free unused memory */
+ newtext = erealloc(newtext, newtextlen+1);
RETURN_STRINGL(newtext, newtextlen, 0);
}