Session handling bug-let?

From: Date: Mon, 15 May 2000 10:19:57 +0000
Subject: Session handling bug-let?
Groups: php.dev 
Request: Send a blank email to php-dev+get-18751@lists.php.net to get a copy of this message
I've noticed a small bug-let in session handling code, as follows: in session.c, in PS_SERIALIZER_DECODE_FUNC(php) we have: for (p = q = val; (p < endptr) && (q = strchr(p, '|')); p = q) { where val is obtained via: (PS(mod)->read(&PS(mod_data), PS(id), &val, &vallen) which for mod_files does: *vallen = sbuf.st_size; *val = emalloc(sbuf.st_size); n = read(data->fd, *val, sbuf.st_size); That means, val is not \0-terminated. That is, it's unsafe to run strchr on it. The obvious solution would be to emalloc one byte more and null-terminate the string. -- Stanislav Malyshev stas@zend.com +972-3-6139665

« previous php.dev (#18751) next »