Session handling bug-let?
| From: | Stanislav Malyshev | Date: | Mon, 15 May 2000 10:19:57 +0000 |
| Subject: | Session handling bug-let? | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-18751@lists.php.net to get a copy of this message | ||
I've noticed a small bug-let in session handling code, as follows:
in session.c, in PS_SERIALIZER_DECODE_FUNC(php) we have:
for (p = q = val; (p < endptr) && (q = strchr(p, '|')); p = q) {
where val is obtained via:
(PS(mod)->read(&PS(mod_data), PS(id), &val, &vallen)
which for mod_files does:
*vallen = sbuf.st_size;
*val = emalloc(sbuf.st_size);
n = read(data->fd, *val, sbuf.st_size);
That means, val is not \0-terminated. That is, it's unsafe to run strchr
on it. The obvious solution would be to emalloc one byte more and
null-terminate the string.
--
Stanislav Malyshev stas@zend.com
+972-3-6139665