[PATCH] Bug #6130: Reproduceable Segfault : imagecolortransparent with 1 argument
| From: | Flavien Lebarbé | Date: | Sun, 20 Aug 2000 21:25:34 +0000 |
| Subject: | [PATCH] Bug #6130: Reproduceable Segfault : imagecolortransparent with 1 argument | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-29961@lists.php.net to get a copy of this message | ||
Hello,
As Martin reported (bug #6130), if the function imagecolortransparent
(ext/gd) is called with only one argument, php segfaults (using
CVS 2 days ago).
Reproducing script (php compiled with gd support) :
---
<?
$i=imagecreate(5,5);
imagecolortransparent($i);
?>
---
From php/ext/gd/gd.c :
---
PHP_FUNCTION(imagecolortransparent)
{
zval **IM, **COL = NULL;
[...]
switch(ZEND_NUM_ARGS()) {
case 1:
if (zend_get_parameters_ex(1, &IM) == FAILURE) {
[...]
}
case 2:
[...]
}
[...]
if ( (*COL) != NULL) {
col = (*COL)->value.lval;
[...]
---
As you can see, if there's only one argument, COL is
initialized to NULL and then we try to access *COL, which
produces a SegFault.
The proposed patch (attached) prevents this.
Please feel free to apply ! :)
Flavien Lebarbé.