Re: Session handling bug-let?
| From: | Sascha Schumann | Date: | Mon, 15 May 2000 10:33:48 +0000 |
| Subject: | Re: Session handling bug-let? | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-18752@lists.php.net to get a copy of this message | ||
On Mon, 15 May 2000, Stanislav Malyshev wrote:
> I've noticed a small bug-let in session handling code, as follows:
>
> in session.c, in PS_SERIALIZER_DECODE_FUNC(php) we have:
>
> for (p = q = val; (p < endptr) && (q = strchr(p, '|')); p = q) {
>
> where val is obtained via:
> (PS(mod)->read(&PS(mod_data), PS(id), &val, &vallen)
>
> which for mod_files does:
>
> *vallen = sbuf.st_size;
> *val = emalloc(sbuf.st_size);
>
> n = read(data->fd, *val, sbuf.st_size);
>
> That means, val is not \0-terminated. That is, it's unsafe to run strchr
> on it. The obvious solution would be to emalloc one byte more and
> null-terminate the string.
The last character of an encoded string is always "|". It was
only unsafe, if something screwed manually with the session
files.
Nevertheless, strchr is sub-optimal here. memchr is faster.
Please try the attached patch and let me know whether it works.
Thanks for pointing out this issue.
- Sascha