Re: Buffer overflow in var_dump()

From: Date: Fri, 09 Jun 2000 14:54:49 +0000
Subject: Re: Buffer overflow in var_dump()
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-20765@lists.php.net to get a copy of this message
It appears as if people are actually using it quite a lot, even if it's for debugging... The problem is that script-level debugging must not be open to buffer overflows, since the users using PHP aren't always trust-worthy. Zeev On Fri, 9 Jun 2000 thies@digicol.de wrote: > On Fri, Jun 09, 2000 at 05:47:29PM +0300, Zeev Suraski wrote: > > > > Given enough nesting levels, the unprotected sprintf()'s in there would > > crash, overflowing buf. We should really get rid of these sprintf()'s, > > I'll do it as soon as I understand the logic behind using them in the > > first place... > > AFAIK the sprintf just does the indenting/formatting - not > really needed. > > var_dump() is not really a function somebody would use on a > live-site - it's a debugging thingie. > > if you feel like changing it - go ahead - i don't see a > reason. > > tc > > > > > Zeev > > > > -- > > Zeev Suraski <zeev@zend.com> > > http://www.zend.com/ > > > > > > -- > > PHP Development Mailing List <http://www.php.net/> > > To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net > > For additional commands, e-mail: php-dev-help@lists.php.net > > To contact the list administrators, e-mail: php-list-admin@lists.php.net > > -- Zeev Suraski <zeev@zend.com> http://www.zend.com/

« previous php.dev (#20765) next »