PHP 4.0 Bug #8498 Updated: Crash due to buffer overflow - suggested patch inside
| From: | rasmus@php.net | Date: | Tue, 02 Jan 2001 20:27:56 +0000 |
| Subject: | PHP 4.0 Bug #8498 Updated: Crash due to buffer overflow - suggested patch inside | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-42670@lists.php.net to get a copy of this message | ||
ID: 8498
Updated by: rasmus
Reported By: johan@ekenberg.se
Old-Status: Open
Status: Closed
Bug Type: Date/time related
Assigned To:
Comments:
Fixed - thanks
Previous Comments:
---------------------------------------------------------------------------
[2000-12-31 07:35:22] johan@ekenberg.se
date("r") prints current time in rfc822 format = 31 characters.
In "ext/standard/datetime.c" (line 491) these 31 chars are copied into a buffer
(tmp_buff) that is only 16 chars long.
On my machine this has caused segmentation faults on various occations.
Suggested patch:
--- datetime.c Sun Dec 31 13:06:48 2000
+++ datetime_fixed.c Sun Dec 31 13:04:41 2000
@@ -214,7 +214,7 @@
time_t the_time;
struct tm *ta, tmbuf;
int i, size = 0, length, h, beat;
- char tmp_buff[16];
+ char tmp_buff[32];
switch(ZEND_NUM_ARGS()) {
case 1:
---------------------------------------------------------------------------
Full Bug description available at: http://bugs.php.net/?id=8498