Re: Ack, #1449 is real

From: Date: Tue, 25 May 1999 15:40:08 +0000
Subject: Re: Ack, #1449 is real
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-5985@lists.php.net to get a copy of this message
Yeah, we are writing madly into memory in the new socket code. This loop in fopen_wrappers.c starting at line 592 overflows the 256 char tmp_line variable. chptr happily goes well past that, and I don't see any sort of check that would attempt to stop it from doing so. Stig, am I missing something here? I believe this is your code. Obviously the assumption here is that a set of response headers will never contain a line longer than 256 chars and that each line will be terminated by a \r a \n or a \r\n and although this appears to be a valid assumption, for some reason *buf keeps ending up '\0' when I step through this and as such this loops forever. So, although the problem isn't likely here, I think this is where we blow away the stack. Adding a check to the while condition there and having the loop terminate if chptr goes above 256 makes the segfault go away, but since SOCK_FGETC returned nothing but \0's the returned array from the file() call is obviously bogus. The question is why isn't SOCK_FGETC() working? while (!body && !SOCK_FEOF(*socketd)) { if (SOCK_FGETC(*socketd) == SOCK_RECV_ERR) { SOCK_FCLOSE(*socketd); *socketd = 0; free_url(resource); return NULL; } oldch5 = oldch4; oldch4 = oldch3; oldch3 = oldch2; oldch2 = oldch1; oldch1 = *buf; tmp_line[chptr++] = *buf; if (*buf == 10 || *buf == 13) { tmp_line[chptr] = '\0'; chptr = 0; if (!strncasecmp(tmp_line, "Location: ", 10)) { tpath = tmp_line + 10; strcpy(location, tpath); } } if (lineone && (*buf == 10 || *buf == 13)) { lineone = 0; } if (lineone && oldch5 == ' ' && oldch4 == '2' && oldch3 == '0' && oldch2 == '0' && oldch1 == ' ') { reqok = 1; } if (oldch4 == 13 && oldch3 == 10 && oldch2 == 13 && oldch1 == 10) { body = 1; } if (oldch2 == 10 && oldch1 == 10) { body = 1; } if (oldch2 == 13 && oldch1 == 13) { body = 1; } } -- PHP Development Mailing List http://www.php.net/ To unsubscribe send an empty message to php-dev-unsubscribe@lists.php.net For help: php-dev-help@lists.php.net

« previous php.dev (#5985) next »