Re: [PATCH] Reproduceable SegFault
| From: | Andi Gutmans | Date: | Sun, 27 Aug 2000 04:04:03 +0000 |
| Subject: | Re: [PATCH] Reproduceable SegFault | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-30797@lists.php.net to get a copy of this message | ||
I'm commiting a patch using strlcpy() which is the easiest and safest way not to overflow strings.
We have both strlcpy() and strlcat() in our source tree, check main/strlcpy.c main/strlcat.c
Thanks for the report.
Andi
At 03:18 AM 8/27/00 +0200, Flavien Lebarbé wrote:
Hi, I tried this tonight : --- <?php for( $i=0;$i<5000;$i++)--- Andi Gutmans <andi@zend.com> http://www.zend.com/$long_one.="a";fsockopen($long_one,$a,$b); ?> --- I got a SegFault. Problematic code :/php4/ext/standard/fsock.c line 312 : strcpy(unix_addr.sun_path, (*args[0])->value.str.val);The problem I have : On my machine, sockaddr_un is defined as : ---"/usr/include/sys/un.h" struct sockaddr_un {sa_family_t sun_family ; char sun_path[108];}; --- So, 108 looks to be a YAMN (Yet Another Magic Number) ... :-( The attached quick-and-dirty patch solves the problem for me.Flavien.--- ext/standard/fsock.c Sun Aug 27 02:26:58 2000+++ ext/standard/fsock.c.orig Mon Jun 19 11:02:48 2000 @@ -309,8 +309,7 @@memset(&unix_addr,(char)0,sizeof(unix_addr)); unix_addr.sun_family = AF_UNIX; - strncpy(unix_addr.sun_path, (*args[0])->value.str.val,108); - unix_addr.sun_path[107]='\0'; + strcpy(unix_addr.sun_path, (*args[0])->value.str.val);if (connect_nonb(socketd, (struct sockaddr *) &unix_addr, sizeof(unix_addr), &timeout) == SOCK_CONN_ERR) { CLOSE_SOCK(1);-- PHP Development Mailing List <http://www.php.net/> To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net For additional commands, e-mail: php-dev-help@lists.php.net To contact the list administrators, e-mail: php-list-admin@lists.php.net