Re: Re: Bug #7238 Updated: Crash caused by is_uploaded function, see also bug#7198
| From: | Zeev Suraski | Date: | Tue, 17 Oct 2000 08:43:29 +0000 |
| Subject: | Re: Re: Bug #7238 Updated: Crash caused by is_uploaded function, see also bug#7198 | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-35227@lists.php.net to get a copy of this message | ||
That's not a very good solution...
At 09:02 17/10/2000, Leena Heino wrote:
Sorry for the mail, but I'm unable to put this information to bug database and change it status. On 16 Oct 2000, Bug Database wrote: ID: 7238 Updated by: sas Reported By: liinu@uta.fi Status: Closed Bug Type: Reproduceable crash Assigned To: Comments: Fixed in CVS. Thanks for your report. Just tested and this in _NOT_ fixed. This still crash the Apache process. The bug is still present in mime.c versio 1.64 lines 252-255: { int dummy=1; _php3_hash_add(&GLOBAL(request_info).rfc1867_uploaded_files, fn, strlen(fn)+1, &dummy, sizeof(int), NULL); } This funtion references &GLOBAL(request_info).rfc1867_uploaded_files variable and this variable does not exist. And this also causes Apache process to crash. And because this &GLOBAL(request_info).rfc1867_uploaded_files is never set and value of this variable always checked at basic_functions.c in is_upload function. Then this is_upload function would always return false. Solution: remove is_upload function from basic_functions.c and basic_functions.h and remove references to &GLOBAL(request_info).rfc1867_uploaded_files in mime.c Full Bug description available at: http://bugs.php.net/?id=7238 -- Leena Heino (liinu@uta.fi) -- PHP Development Mailing List <http://www.php.net/> To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net For additional commands, e-mail: php-dev-help@lists.php.net To contact the list administrators, e-mail: php-list-admin@lists.php.net-- Zeev Suraski <zeev@zend.com> http://www.zend.com/