PHP 4.0 Bug #8381: Crash in call_user_function_ex

From: Date: Fri, 22 Dec 2000 19:32:26 +0000
Subject: PHP 4.0 Bug #8381: Crash in call_user_function_ex
Groups: php.dev 
Request: Send a blank email to php-dev+get-42132@lists.php.net to get a copy of this message
From: lou@montulli.org Operating system: linux PHP version: 4.0.4 PHP Bug Type: Reproduceable crash Bug description: Crash in call_user_function_ex This bug was triggered by a bad call from xml_call_handler. call_user_function_ex takes a void** pointer from the caller and doubly dereferences the pointer in the macro call Z_TYPE_PP on line 365 of zend_execute_API.c I suggest the following change to make zend_execute_API.c crash safe. diff -c -r1.1.1.1 zend_execute_API.c *** zend_execute_API.c 2000/12/22 00:13:44 1.1.1.1 --- zend_execute_API.c 2000/12/22 19:30:46 *************** *** 362,368 **** } if (object_pp) { ! if (Z_TYPE_PP(object_pp) != IS_OBJECT) { return FAILURE; } function_table = &(*object_pp)->value.obj.ce->function_table; --- 362,368 ---- } if (object_pp) { ! if (!*object_pp || Z_TYPE_PP(object_pp) != IS_OBJECT) { return FAILURE; } function_table = &(*object_pp)->value.obj.ce->function_table; In addition, to fix the real problem the following change to xml.c diff -r1.1.1.1 xml.c 361c361 < result = call_user_function(EG(function_table), &parser->object, handler, retval, argc, argv); --- > result = call_user_function(EG(function_table), parser->object ? &parser->object : > NULL, handler, retval, argc, argv); :lou http://montulli.org/lou/ -- Edit Bug report at: http://bugs.php.net/?id=8381&edit=1

« previous php.dev (#42132) next »