cvs: /php3/functions head.c
| From: | Thies C. Arntzen | Date: | Sun, 06 Feb 2000 14:40:47 +0000 |
| Subject: | cvs: /php3/functions head.c | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-15248@lists.php.net to get a copy of this message | ||
thies Sun Feb 6 06:40:47 2000 EDT
Modified files:
/php3/functions head.c
Log:
fix for #3413 -> possible buffer-overflow in setcookie()
Index: php3/functions/head.c
diff -u php3/functions/head.c:1.123 php3/functions/head.c:1.124
--- php3/functions/head.c:1.123 Fri Dec 31 20:31:15 1999
+++ php3/functions/head.c Sun Feb 6 06:40:47 2000
@@ -26,7 +26,7 @@
| Authors: Rasmus Lerdorf <rasmus@lerdorf.on.ca> |
+----------------------------------------------------------------------+
*/
-/* $Id: head.c,v 1.123 2000/01/01 04:31:15 sas Exp $ */
+/* $Id: head.c,v 1.124 2000/02/06 14:40:47 thies Exp $ */
#include <stdio.h>
#include "php.h"
#include "internal_functions.h"
@@ -450,7 +450,7 @@
#endif
int len=0;
time_t t;
- char *r, *dt;
+ char *dt,*encoded_value=NULL;
#endif
#if APACHE
if (name) name = estrdup(name);
@@ -460,7 +460,10 @@
php3_PushCookieList(name, value, expires, path, domain, secure);
#else
if (name) len += strlen(name);
- if (value) len += strlen(value);
+ if (value) {
+ encoded_value = _php3_urlencode(value, strlen (value));
+ len += strlen(encoded_value);
+ }
if (path) len += strlen(path);
if (domain) len += strlen(domain);
tempstr = emalloc(len + 100);
@@ -478,9 +481,7 @@
efree(dt);
} else {
/* FIXME: XXX: this is not binary data safe */
- r = _php3_urlencode(value, strlen (value));
- sprintf(tempstr, "%s=%s", name, value ? r : "");
- if (r) efree(r);
+ sprintf(tempstr, "%s=%s", name, value ? encoded_value : "");
if (expires > 0) {
strcat(tempstr, "; expires=");
dt = php3_std_date(expires);
@@ -488,6 +489,9 @@
efree(dt);
}
}
+
+ if (encoded_value) efree(encoded_value);
+
if (path && strlen(path)) {
strcat(tempstr, "; path=");
strcat(tempstr, path);