com php-src: fix leak in 7.0: ext/session/mod_files.c
| From: | Anatol Belski | Date: | Fri, 29 Jan 2016 13:48:05 +0000 |
| Subject: | com php-src: fix leak in 7.0: ext/session/mod_files.c | ||
| Groups: | php.cvs | ||
| Request: | Send a blank email to php-cvs+get-90794@lists.php.net to get a copy of this message | ||
Commit: ee49df011ce55f088908c54ef24ce4db45574414
Author: Anatol Belski <ab@php.net> Fri, 29 Jan 2016 14:37:46 +0100
Parents: a0d7a667567e6a995557fee6465104a323d18deb
Branches: PHP-7.0 master
Link: http://git.php.net/?p=php-src.git;a=commitdiff;h=ee49df011ce55f088908c54ef24ce4db45574414
Log:
fix leak in 7.0
Changed paths:
M ext/session/mod_files.c
Diff:
diff --git a/ext/session/mod_files.c b/ext/session/mod_files.c
index b380cfe..8f2edca 100644
--- a/ext/session/mod_files.c
+++ b/ext/session/mod_files.c
@@ -115,7 +115,7 @@ static char *ps_files_path_create(char *buf, size_t buflen, ps_files *data, cons
key_len = strlen(key);
if (key_len <= data->dirdepth ||
- buflen < (strlen(data->basedir) + 2 * data->dirdepth + key_len + 5 +
sizeof(FILE_PREFIX))) {
+ buflen < (data->basedir_len + 2 * data->dirdepth + key_len + 5 + sizeof(FILE_PREFIX))) {
return NULL;
}
@@ -170,6 +170,11 @@ static void ps_files_open(ps_files *data, const char *key)
ps_files_close(data);
if (php_session_valid_key(key) == FAILURE) {
+ if (data->basedir) {
+ efree(data->basedir);
+ data->basedir = NULL;
+ data->basedir_len = 0;
+ }
php_error_docref(NULL, E_WARNING, "The session id is too long or contains illegal
characters, valid characters are a-z, A-Z, 0-9 and '-,'");
return;
}