Re: Session handling bug-let?

From: Date: Mon, 15 May 2000 10:33:48 +0000
Subject: Re: Session handling bug-let?
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-18752@lists.php.net to get a copy of this message
On Mon, 15 May 2000, Stanislav Malyshev wrote: > I've noticed a small bug-let in session handling code, as follows: > > in session.c, in PS_SERIALIZER_DECODE_FUNC(php) we have: > > for (p = q = val; (p < endptr) && (q = strchr(p, '|')); p = q) { > > where val is obtained via: > (PS(mod)->read(&PS(mod_data), PS(id), &val, &vallen) > > which for mod_files does: > > *vallen = sbuf.st_size; > *val = emalloc(sbuf.st_size); > > n = read(data->fd, *val, sbuf.st_size); > > That means, val is not \0-terminated. That is, it's unsafe to run strchr > on it. The obvious solution would be to emalloc one byte more and > null-terminate the string. The last character of an encoded string is always "|". It was only unsafe, if something screwed manually with the session files. Nevertheless, strchr is sub-optimal here. memchr is faster. Please try the attached patch and let me know whether it works. Thanks for pointing out this issue. - Sascha

« previous php.dev (#18752) next »