Re: Oracle bug

From: Date: Thu, 08 Jun 2000 09:55:17 +0000
Subject: Re: Oracle bug
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-20551@lists.php.net to get a copy of this message
On Wed, Jun 07, 2000 at 11:45:04AM -0700, Rasmus Lerdorf wrote: > Thies, I think I found an oversight in the oci8 code. Take this simple > script: > > $conn = ocilogon('delta_u','delta_u','ddb01') or die; > $stmt = ociparse($conn,"select * from d_customer where > cust_username='bogus'"); > OCIExecute($stmt); > ocifetch($stmt); > $nrows=OCIFetchStatement($stmt,$results); > > The query itself returns 0 rows. And yes, I know it is bogus to call > ocifetch() and then OCIFetchStatement(), however this script causes a core > dump in both PHP 3 and 4 because there is no error checking in > ocifetchstatement(). The code is: > > columns[ i ] = oci_get_col(statement, i + 1, 0); > > MAKE_STD_ZVAL(tmp); > array_init(tmp); > > memcpy(namebuf,columns[ i ]->name, columns[ i ]->name_len); > namebuf[ columns[ i ]->name_len ] = 0; > > oci_get_col() will return NULL in this scenario and there is no check for > that before you try to dereference it in the memcpy() call. Predictably I > get a core dump on the memcpy() call. fixed in 3 & 4. thanx for spotting. > > -Rasmus

« previous php.dev (#20551) next »