PHP 4.0 Bug #4795: Memory leak on invalid handle in fd_set()
| From: | clcollie at mindspring dot com | Date: | Sat, 03 Jun 2000 16:30:11 +0000 |
| Subject: | PHP 4.0 Bug #4795: Memory leak on invalid handle in fd_set() | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-20131@lists.php.net to get a copy of this message | ||
From: clcollie@mindspring.com
Operating system: Linux Mandrake 7.0
PHP version: 4.0.0 Release
PHP Bug Type: Scripting Engine problem
Bug description: Memory leak on invalid handle in fd_set()
fd_set will leak memory if an invalid handle is passed in as a parameter. the offending section of
code follows :
pval ***args = (pval ***) emalloc(sizeof(pval **) * ARG_COUNT(ht));
int i;
if(zend_get_parameters_array_ex(ARG_COUNT(ht), args) == FAILURE) {
efree(args);
WRONG_PARAM_COUNT;
}
FD_ZERO(&readfd);
for(i = 0; i < ARG_COUNT(ht); i++) {
what =
zend_fetch_resource(*args,-1,"select",&type,3,le_fopen,le_socket,le_popen);
ZEND_VERIFY_RESOURCE(what);
[... snip ...]
}
FD_SET(fd, &readfd);
if(fd > max_fd) max_fd = fd;
}
the problem is that the macro ZEND_VERIFY_RESOURCE exits the function with an error value if the
parameter is not a resource, without there being any cleanup of args i.e. efree(args)
clayton collie
PHPnut