PHP 4.0 Bug #7707 Updated: multipart forms with file uploads cause segfaults

From: Date: Wed, 08 Nov 2000 21:16:29 +0000
Subject: PHP 4.0 Bug #7707 Updated: multipart forms with file uploads cause segfaults
Groups: php.dev 
Request: Send a blank email to php-dev+get-37459@lists.php.net to get a copy of this message
ID: 7707 Updated by: rasmus Reported By: nalin+bugs-php-net@redhat.com Status: Closed Bug Type: Reproduceable crash Assigned To: Comments: This was fixed on October 17: http://cvs.php.net/viewcvs.cgi/php3/functions/mime.c.diff?r1=1.63&r2=1.64 and http://cvs.php.net/viewcvs.cgi/php3/request_info.c.diff?r1=1.44&r2=1.45 Previous Comments: --------------------------------------------------------------------------- [2000-11-08 15:58:35] nalin+bugs-php-net@redhat.com It looks like the new safety code in 3.0.17 implicitly assumes that all data supplied by a multipart/form-data request have filename attributes, so when PHP goes to parse out the filename it attempts to take strlen() of a NULL pointer at functions/mime.c:187. After adding a check for that, it looks like the rfc1867_uploaded_files hash table in the request_info record is only initialized if PHP is built as a CGI, and if not, an attempt to access the hash table's hashing function causes another segfault. Adding this patch appears to fix the segfaults, but I don't yet know if this breaks the security checks or not. If the bug-reporting system messes up the patch, I'll be happy to email it. --- php-3.0.17/functions/mime.c Mon Nov 6 15:46:38 2000 +++ php-3.0.17/functions/mime.c Mon Nov 6 18:22:21 2000 @@ -184,7 +184,7 @@ *(loc - 4) = '

« previous php.dev (#37459) next »