[PATCH] Bug #6130: Reproduceable Segfault : imagecolortransparent with 1 argument

From: Date: Sun, 20 Aug 2000 21:25:34 +0000
Subject: [PATCH] Bug #6130: Reproduceable Segfault : imagecolortransparent with 1 argument
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-29961@lists.php.net to get a copy of this message
Hello, As Martin reported (bug #6130), if the function imagecolortransparent (ext/gd) is called with only one argument, php segfaults (using CVS 2 days ago). Reproducing script (php compiled with gd support) : --- <? $i=imagecreate(5,5); imagecolortransparent($i); ?> --- From php/ext/gd/gd.c : --- PHP_FUNCTION(imagecolortransparent) { zval **IM, **COL = NULL; [...] switch(ZEND_NUM_ARGS()) { case 1: if (zend_get_parameters_ex(1, &IM) == FAILURE) { [...] } case 2: [...] } [...] if ( (*COL) != NULL) { col = (*COL)->value.lval; [...] --- As you can see, if there's only one argument, COL is initialized to NULL and then we try to access *COL, which produces a SegFault. The proposed patch (attached) prevents this. Please feel free to apply ! :) Flavien Lebarbé.

« previous php.dev (#29961) next »