Bug #2501: Buffer overflow causing segfault in date()
| From: | dharple at mail dot communityconnect dot com | Date: | Tue, 12 Oct 1999 22:30:00 +0000 |
| Subject: | Bug #2501: Buffer overflow causing segfault in date() | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-11709@lists.php.net to get a copy of this message | ||
From: dharple@mail.communityconnect.com
Operating system: Linux (any really)
PHP version: 3.0.12
PHP Bug Type: Misbehaving function
Bug description: Buffer overflow causing segfault in date()
In _php3_date, the for loop that determines the size of the string to create is missing a case for
'g', causing the calculated size to be off by one. The problem only appears to show up
under Linux (making me think there's something else wrong as well).
The PHP code that caused the problem was:
$fo = date( "D, M d, Y @ g:i a", $ts ) ;
I only discovered it after rigorous debugging, as it doesn't cause a seg fault all the time.
It would only occur if the hour ('g') and the day of the month ('d') was greater
than 9, and it wouldn't always occur then (I don't know why).
To work around it, I added an extra space at the end of the 'a'.