Re: Ack, #1449 is real
| From: | Rasmus Lerdorf | Date: | Tue, 25 May 1999 15:40:08 +0000 |
| Subject: | Re: Ack, #1449 is real | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-5985@lists.php.net to get a copy of this message | ||
Yeah, we are writing madly into memory in the new socket code.
This loop in fopen_wrappers.c starting at line 592 overflows the 256 char
tmp_line variable. chptr happily goes well past that, and I don't see any
sort of check that would attempt to stop it from doing so.
Stig, am I missing something here? I believe this is your code.
Obviously the assumption here is that a set of response headers will never
contain a line longer than 256 chars and that each line will be terminated
by a \r a \n or a \r\n and although this appears to be a valid assumption,
for some reason *buf keeps ending up '\0' when I step through this and as
such this loops forever. So, although the problem isn't likely here, I
think this is where we blow away the stack. Adding a check to the while
condition there and having the loop terminate if chptr goes above 256
makes the segfault go away, but since SOCK_FGETC returned nothing but \0's
the returned array from the file() call is obviously bogus. The question
is why isn't SOCK_FGETC() working?
while (!body && !SOCK_FEOF(*socketd)) {
if (SOCK_FGETC(*socketd) == SOCK_RECV_ERR) {
SOCK_FCLOSE(*socketd);
*socketd = 0;
free_url(resource);
return NULL;
}
oldch5 = oldch4;
oldch4 = oldch3;
oldch3 = oldch2;
oldch2 = oldch1;
oldch1 = *buf;
tmp_line[chptr++] = *buf;
if (*buf == 10 || *buf == 13) {
tmp_line[chptr] = '\0';
chptr = 0;
if (!strncasecmp(tmp_line, "Location: ", 10)) {
tpath = tmp_line + 10;
strcpy(location, tpath);
}
}
if (lineone && (*buf == 10 || *buf == 13)) {
lineone = 0;
}
if (lineone && oldch5 == ' ' && oldch4 == '2'
&& oldch3 == '0'
&&
oldch2 == '0' && oldch1 == ' ') {
reqok = 1;
}
if (oldch4 == 13 && oldch3 == 10 && oldch2 == 13 && oldch1 ==
10) {
body = 1;
}
if (oldch2 == 10 && oldch1 == 10) {
body = 1;
}
if (oldch2 == 13 && oldch1 == 13) {
body = 1;
}
}
--
PHP Development Mailing List http://www.php.net/
To unsubscribe send an empty message to php-dev-unsubscribe@lists.php.net
For help: php-dev-help@lists.php.net