Oracle bug

From: Date: Wed, 07 Jun 2000 18:45:04 +0000
Subject: Oracle bug
Groups: php.dev 
Request: Send a blank email to php-dev+get-20490@lists.php.net to get a copy of this message
Thies, I think I found an oversight in the oci8 code. Take this simple script: $conn = ocilogon('delta_u','delta_u','ddb01') or die; $stmt = ociparse($conn,"select * from d_customer where cust_username='bogus'"); OCIExecute($stmt); ocifetch($stmt); $nrows=OCIFetchStatement($stmt,$results); The query itself returns 0 rows. And yes, I know it is bogus to call ocifetch() and then OCIFetchStatement(), however this script causes a core dump in both PHP 3 and 4 because there is no error checking in ocifetchstatement(). The code is: columns[ i ] = oci_get_col(statement, i + 1, 0); MAKE_STD_ZVAL(tmp); array_init(tmp); memcpy(namebuf,columns[ i ]->name, columns[ i ]->name_len); namebuf[ columns[ i ]->name_len ] = 0; oci_get_col() will return NULL in this scenario and there is no check for that before you try to dereference it in the memcpy() call. Predictably I get a core dump on the memcpy() call. -Rasmus

« previous php.dev (#20490) next »