PHP 4.0 Bug #8381: Crash in call_user_function_ex
| From: | lou at montulli dot org | Date: | Fri, 22 Dec 2000 19:32:26 +0000 |
| Subject: | PHP 4.0 Bug #8381: Crash in call_user_function_ex | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-42132@lists.php.net to get a copy of this message | ||
From: lou@montulli.org
Operating system: linux
PHP version: 4.0.4
PHP Bug Type: Reproduceable crash
Bug description: Crash in call_user_function_ex
This bug was triggered by a bad call from xml_call_handler.
call_user_function_ex takes a void** pointer from the caller and doubly dereferences the pointer in
the macro call Z_TYPE_PP on line 365 of zend_execute_API.c
I suggest the following change to make zend_execute_API.c crash safe.
diff -c -r1.1.1.1 zend_execute_API.c
*** zend_execute_API.c 2000/12/22 00:13:44 1.1.1.1
--- zend_execute_API.c 2000/12/22 19:30:46
***************
*** 362,368 ****
}
if (object_pp) {
! if (Z_TYPE_PP(object_pp) != IS_OBJECT) {
return FAILURE;
}
function_table = &(*object_pp)->value.obj.ce->function_table;
--- 362,368 ----
}
if (object_pp) {
! if (!*object_pp || Z_TYPE_PP(object_pp) != IS_OBJECT) {
return FAILURE;
}
function_table = &(*object_pp)->value.obj.ce->function_table;
In addition, to fix the real problem the following change to xml.c
diff -r1.1.1.1 xml.c
361c361
< result = call_user_function(EG(function_table), &parser->object, handler, retval,
argc, argv);
---
> result = call_user_function(EG(function_table), parser->object ? &parser->object :
> NULL, handler, retval, argc, argv);
:lou
http://montulli.org/lou/
--
Edit Bug report at: http://bugs.php.net/?id=8381&edit=1