PHP 4.0 Bug #7577: Reporducable curl_exec() segfault

From: Date: Wed, 01 Nov 2000 23:08:21 +0000
Subject: PHP 4.0 Bug #7577: Reporducable curl_exec() segfault
Groups: php.dev 
Request: Send a blank email to php-dev+get-36721@lists.php.net to get a copy of this message
From: torben@php.net Operating system: Mandrake 7.0 PHP version: 4.0 Latest CVS (01/11/2000) PHP Bug Type: Reproduceable crash Bug description: Reporducable curl_exec() segfault An empty value in the array given to curl_setopt() with CURLOPT_QUOTE or CURLOPT_POSTQUOTE causes PHP to segfault in the curl library: <?php /* -*- mode: c++; minor-mode: font -*- */ error_reporting(E_ALL); $url = 'ftp://ftp.thebuttlesschaps.com'; $userpwd = 'thebuttl:*******'; /* Contrived for illustration. */ $ftp_quote = array('cwd htdocs', false, 'cwd /'); $curld = curl_init(); curl_setopt($curld, CURLOPT_URL, $url); curl_setopt($curld, CURLOPT_USERPWD, $userpwd); curl_setopt($curld, CURLOPT_QUOTE, $ftp_quote); curl_setopt($curld, CURLOPT_VERBOSE, true); curl_exec($curld); curl_close($curld); ?> Backtrace: ~/work/php4 shanna% gdb ./php GNU gdb 19991116 Copyright 1998 Free Software Foundation, Inc. GDB is free software, covered by the GNU General Public License, and you are welcome to change it and/or distribute copies of it under certain conditions. Type "show copying" to see the conditions. There is absolutely no warranty for GDB. Type "show warranty" for details. This GDB was configured as "i586-mandrake-linux"... (gdb) run -q ~/public_html/php3test/curlcrash.html Starting program: /home/www/work/php4/./php -q ~/public_html/php3test/curlcrash.html < 220 ftp2.hostme.com FTP server (Version wu-2.6.0(1) Tue Jul 11 20:31:53 EDT 2000) ready. > USER thebuttl < 331 Password required for thebuttl. > PASS ******** < 230-Please read the file README < 230- it was last modified on Fri May 7 19:39:51 1999 - 544 days ago < 230 User thebuttl logged in. * We have successfully logged in * Connected to ftp.thebuttlesschaps.com (206.245.164.13) Program received signal SIGSEGV, Segmentation fault. 0x4014aefa in mvaprintf (format=0x4014e9e6 "%s", ap_save=0xbfffa0e0) at mprintf.c:1151 1151 info.buffer[info.len] = 0; /* we terminate this with a zero byte */ (gdb) bt #0 0x4014aefa in mvaprintf (format=0x4014e9e6 "%s", ap_save=0xbfffa0e0) at mprintf.c:1151 #1 0x40142121 in ftpsendf (fd=7, conn=0x81d11b0, fmt=0x4014e9e6 "%s") at sendf.c:133 #2 0x40142eca in _ftp (conn=0x81d11b0) at ftp.c:628 #3 0x40144553 in ftp (conn=0x81d11b0) at ftp.c:1420 #4 0x401472e0 in curl_do (in_conn=0x81d11b0) at url.c:1516 #5 0x4014d98c in curl_transfer (curl=0x81d6268) at highlevel.c:629 #6 0x4014dd6b in curl_easy_perform (curl=0x81d6268) at easy.c:157 #7 0x806b38f in php_if_curl_exec (ht=1, return_value=0x81d6064, this_ptr=0x0, return_value_used=0) at curl.c:597 #8 0x810baef in execute (op_array=0x81d109c) at ./zend_execute.c:1519 #9 0x80e3f5b in zend_execute_scripts (type=8, file_count=3) at zend.c:717 #10 0x80639f4 in php_execute_script (primary_file=0xbffff9c8) at main.c:1210 #11 0x8062004 in main (argc=3, argv=0xbffffa44) at cgi_main.c:725 (gdb) quit This patch seems to fix it: Index: curl.c =================================================================== RCS file: /repository/php4/ext/curl/curl.c,v retrieving revision 1.21 diff -u -r1.21 curl.c --- curl.c 2000/10/27 19:10:21 1.21 +++ curl.c 2000/11/01 22:41:25 @@ -533,6 +533,10 @@ SEPARATE_ZVAL(current); convert_to_string_ex(current); + + if (Z_STRLEN_PP(current) < 1) { + continue; + } indiv_command = estrndup(Z_STRVAL_PP(current), Z_STRLEN_PP(current)); commands = curl_slist_append(commands, indiv_command); -- Edit Bug report at: http://bugs.php.net/?id=7577&edit=1

« previous php.dev (#36721) next »