Oracle bug
| From: | Rasmus Lerdorf | Date: | Wed, 07 Jun 2000 18:45:04 +0000 |
| Subject: | Oracle bug | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-20490@lists.php.net to get a copy of this message | ||
Thies, I think I found an oversight in the oci8 code. Take this simple
script:
$conn = ocilogon('delta_u','delta_u','ddb01') or die;
$stmt = ociparse($conn,"select * from d_customer where
cust_username='bogus'");
OCIExecute($stmt);
ocifetch($stmt);
$nrows=OCIFetchStatement($stmt,$results);
The query itself returns 0 rows. And yes, I know it is bogus to call
ocifetch() and then OCIFetchStatement(), however this script causes a core
dump in both PHP 3 and 4 because there is no error checking in
ocifetchstatement(). The code is:
columns[ i ] = oci_get_col(statement, i + 1, 0);
MAKE_STD_ZVAL(tmp);
array_init(tmp);
memcpy(namebuf,columns[ i ]->name, columns[ i ]->name_len);
namebuf[ columns[ i ]->name_len ] = 0;
oci_get_col() will return NULL in this scenario and there is no check for
that before you try to dereference it in the memcpy() call. Predictably I
get a core dump on the memcpy() call.
-Rasmus