PHP 4.0 Bug #7707 Updated: multipart forms with file uploads cause segfaults
| From: | rasmus@php.net | Date: | Wed, 08 Nov 2000 21:16:29 +0000 |
| Subject: | PHP 4.0 Bug #7707 Updated: multipart forms with file uploads cause segfaults | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-37459@lists.php.net to get a copy of this message | ||
ID: 7707
Updated by: rasmus
Reported By: nalin+bugs-php-net@redhat.com
Status: Closed
Bug Type: Reproduceable crash
Assigned To:
Comments:
This was fixed on October 17:
http://cvs.php.net/viewcvs.cgi/php3/functions/mime.c.diff?r1=1.63&r2=1.64
and
http://cvs.php.net/viewcvs.cgi/php3/request_info.c.diff?r1=1.44&r2=1.45
Previous Comments:
---------------------------------------------------------------------------
[2000-11-08 15:58:35] nalin+bugs-php-net@redhat.com
It looks like the new safety code in 3.0.17 implicitly assumes that all data supplied by a
multipart/form-data request have filename attributes, so when PHP goes to parse out the filename it
attempts to take strlen() of a NULL pointer at functions/mime.c:187.
After adding a check for that, it looks like the rfc1867_uploaded_files hash table in the
request_info record is only initialized if PHP is built as a CGI, and if not, an attempt to access
the hash table's hashing function causes another segfault.
Adding this patch appears to fix the segfaults, but I don't yet know if this breaks the
security checks or not.
If the bug-reporting system messes up the patch, I'll be happy to email it.
--- php-3.0.17/functions/mime.c Mon Nov 6 15:46:38 2000
+++ php-3.0.17/functions/mime.c Mon Nov 6 18:22:21 2000
@@ -184,7 +184,7 @@
*(loc - 4) = '