PHP 4.0 Bug #8381 Updated: Crash in call_user_function_ex
| From: | sniper@php.net | Date: | Thu, 28 Dec 2000 10:53:59 +0000 |
| Subject: | PHP 4.0 Bug #8381 Updated: Crash in call_user_function_ex | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-42373@lists.php.net to get a copy of this message | ||
ID: 8381
Updated by: sniper
Reported By: lou@montulli.org
Old-Status: Open
Status: Closed
Bug Type: Reproduceable crash
Assigned To:
Comments:
AFAIK, this should be fixed in CVs.
Please try the latest snapshot from http://snaps.php.net/
and reopen this bug report if problem still exists.
--Jani
Previous Comments:
---------------------------------------------------------------------------
[2000-12-22 14:32:26] lou@montulli.org
This bug was triggered by a bad call from xml_call_handler.
call_user_function_ex takes a void** pointer from the caller and doubly dereferences the pointer in
the macro call Z_TYPE_PP on line 365 of zend_execute_API.c
I suggest the following change to make zend_execute_API.c crash safe.
diff -c -r1.1.1.1 zend_execute_API.c
*** zend_execute_API.c 2000/12/22 00:13:44 1.1.1.1
--- zend_execute_API.c 2000/12/22 19:30:46
***************
*** 362,368 ****
}
if (object_pp) {
! if (Z_TYPE_PP(object_pp) != IS_OBJECT) {
return FAILURE;
}
function_table = &(*object_pp)->value.obj.ce->function_table;
--- 362,368 ----
}
if (object_pp) {
! if (!*object_pp || Z_TYPE_PP(object_pp) != IS_OBJECT) {
return FAILURE;
}
function_table = &(*object_pp)->value.obj.ce->function_table;
In addition, to fix the real problem the following change to xml.c
diff -r1.1.1.1 xml.c
361c361
< result = call_user_function(EG(function_table), &parser->object, handler, retval,
argc, argv);
---
> result = call_user_function(EG(function_table), parser->object ? &parser->object :
> NULL, handler, retval, argc, argv);
:lou
http://montulli.org/lou/
---------------------------------------------------------------------------
Full Bug description available at: http://bugs.php.net/?id=8381