PHP 4.0 Bug #7577: Reporducable curl_exec() segfault
| From: | torben@php.net | Date: | Wed, 01 Nov 2000 23:08:21 +0000 |
| Subject: | PHP 4.0 Bug #7577: Reporducable curl_exec() segfault | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-36721@lists.php.net to get a copy of this message | ||
From: torben@php.net
Operating system: Mandrake 7.0
PHP version: 4.0 Latest CVS (01/11/2000)
PHP Bug Type: Reproduceable crash
Bug description: Reporducable curl_exec() segfault
An empty value in the array given to curl_setopt() with
CURLOPT_QUOTE or CURLOPT_POSTQUOTE causes PHP to segfault
in the curl library:
<?php /* -*- mode: c++; minor-mode: font -*- */
error_reporting(E_ALL);
$url = 'ftp://ftp.thebuttlesschaps.com';
$userpwd = 'thebuttl:*******';
/* Contrived for illustration. */
$ftp_quote = array('cwd htdocs', false, 'cwd /');
$curld = curl_init();
curl_setopt($curld, CURLOPT_URL, $url);
curl_setopt($curld, CURLOPT_USERPWD, $userpwd);
curl_setopt($curld, CURLOPT_QUOTE, $ftp_quote);
curl_setopt($curld, CURLOPT_VERBOSE, true);
curl_exec($curld);
curl_close($curld);
?>
Backtrace:
~/work/php4
shanna% gdb ./php
GNU gdb 19991116
Copyright 1998 Free Software Foundation, Inc.
GDB is free software, covered by the GNU General Public License, and you are
welcome to change it and/or distribute copies of it under certain conditions.
Type "show copying" to see the conditions.
There is absolutely no warranty for GDB. Type "show warranty" for details.
This GDB was configured as "i586-mandrake-linux"...
(gdb) run -q ~/public_html/php3test/curlcrash.html
Starting program: /home/www/work/php4/./php -q ~/public_html/php3test/curlcrash.html
< 220 ftp2.hostme.com FTP server (Version wu-2.6.0(1) Tue Jul 11 20:31:53 EDT 2000) ready.
> USER thebuttl
< 331 Password required for thebuttl.
> PASS ********
< 230-Please read the file README
< 230- it was last modified on Fri May 7 19:39:51 1999 - 544 days ago
< 230 User thebuttl logged in.
* We have successfully logged in
* Connected to ftp.thebuttlesschaps.com (206.245.164.13)
Program received signal SIGSEGV, Segmentation fault.
0x4014aefa in mvaprintf (format=0x4014e9e6 "%s", ap_save=0xbfffa0e0) at mprintf.c:1151
1151 info.buffer[info.len] = 0; /* we terminate this with a zero byte */
(gdb) bt
#0 0x4014aefa in mvaprintf (format=0x4014e9e6 "%s", ap_save=0xbfffa0e0) at mprintf.c:1151
#1 0x40142121 in ftpsendf (fd=7, conn=0x81d11b0, fmt=0x4014e9e6 "%s") at sendf.c:133
#2 0x40142eca in _ftp (conn=0x81d11b0) at ftp.c:628
#3 0x40144553 in ftp (conn=0x81d11b0) at ftp.c:1420
#4 0x401472e0 in curl_do (in_conn=0x81d11b0) at url.c:1516
#5 0x4014d98c in curl_transfer (curl=0x81d6268) at highlevel.c:629
#6 0x4014dd6b in curl_easy_perform (curl=0x81d6268) at easy.c:157
#7 0x806b38f in php_if_curl_exec (ht=1, return_value=0x81d6064, this_ptr=0x0,
return_value_used=0) at curl.c:597
#8 0x810baef in execute (op_array=0x81d109c) at ./zend_execute.c:1519
#9 0x80e3f5b in zend_execute_scripts (type=8, file_count=3) at zend.c:717
#10 0x80639f4 in php_execute_script (primary_file=0xbffff9c8) at main.c:1210
#11 0x8062004 in main (argc=3, argv=0xbffffa44) at cgi_main.c:725
(gdb) quit
This patch seems to fix it:
Index: curl.c
===================================================================
RCS file: /repository/php4/ext/curl/curl.c,v
retrieving revision 1.21
diff -u -r1.21 curl.c
--- curl.c 2000/10/27 19:10:21 1.21
+++ curl.c 2000/11/01 22:41:25
@@ -533,6 +533,10 @@
SEPARATE_ZVAL(current);
convert_to_string_ex(current);
+
+ if (Z_STRLEN_PP(current) < 1) {
+ continue;
+ }
indiv_command = estrndup(Z_STRVAL_PP(current), Z_STRLEN_PP(current));
commands = curl_slist_append(commands, indiv_command);
--
Edit Bug report at: http://bugs.php.net/?id=7577&edit=1