Re: Bug #7238 Updated: Crash caused by is_uploaded function, see also bug#7198
| From: | Leena Heino | Date: | Thu, 01 Jan 1970 00:00:00 +0000 |
| Subject: | Re: Bug #7238 Updated: Crash caused by is_uploaded function, see also bug#7198 | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-35225@lists.php.net to get a copy of this message | ||
Sorry for the mail, but I'm unable to put this information to bug database
and change it status.
On 16 Oct 2000, Bug Database wrote:
> ID: 7238
> Updated by: sas
> Reported By: liinu@uta.fi
> Status: Closed
> Bug Type: Reproduceable crash
> Assigned To:
> Comments:
>
> Fixed in CVS. Thanks for your report.
>
Just tested and this in _NOT_ fixed. This still crash the Apache
process. The bug is still present in mime.c versio 1.64 lines 252-255:
{
int dummy=1;
_php3_hash_add(&GLOBAL(request_info).rfc1867_uploaded_files, fn,
strlen(fn)+1, &dummy, sizeof(int), NULL);
}
This funtion references &GLOBAL(request_info).rfc1867_uploaded_files
variable and this variable does not exist. And this also causes Apache
process to crash.
And because this &GLOBAL(request_info).rfc1867_uploaded_files is
never set and value of this variable always checked at basic_functions.c
in is_upload function. Then this is_upload function would always return
false.
Solution: remove is_upload function from basic_functions.c and
basic_functions.h and remove references to
&GLOBAL(request_info).rfc1867_uploaded_files in mime.c
> Full Bug description available at: http://bugs.php.net/?id=7238
>
-- Leena Heino (liinu@uta.fi)