Re: Ack, #1449 is real

From: Date: Wed, 26 May 1999 09:49:54 +0000
Subject: Re: Ack, #1449 is real
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-6011@lists.php.net to get a copy of this message
This stopped as of the final 3.0.8 release. It should not have crept into 3.0.8 :-P. I didn't get time to test Sascha's new code before it was released, but yesterday I found exactly the same bug on Solaris. Looking into it. We probably need to release 3.0.9 pretty soon. - Stig On Tue, 25 May 1999, Rasmus Lerdorf wrote: > Yeah, we are writing madly into memory in the new socket code. > > This loop in fopen_wrappers.c starting at line 592 overflows the 256 char > tmp_line variable. chptr happily goes well past that, and I don't see any > sort of check that would attempt to stop it from doing so. > > Stig, am I missing something here? I believe this is your code. > Obviously the assumption here is that a set of response headers will never > contain a line longer than 256 chars and that each line will be terminated > by a \r a \n or a \r\n and although this appears to be a valid assumption, > for some reason *buf keeps ending up '\0' when I step through this and as > such this loops forever. So, although the problem isn't likely here, I > think this is where we blow away the stack. Adding a check to the while > condition there and having the loop terminate if chptr goes above 256 > makes the segfault go away, but since SOCK_FGETC returned nothing but \0's > the returned array from the file() call is obviously bogus. The question > is why isn't SOCK_FGETC() working? > > while (!body && !SOCK_FEOF(*socketd)) { > if (SOCK_FGETC(*socketd) == SOCK_RECV_ERR) { > SOCK_FCLOSE(*socketd); > *socketd = 0; > free_url(resource); > return NULL; > } > oldch5 = oldch4; > oldch4 = oldch3; > oldch3 = oldch2; > oldch2 = oldch1; > oldch1 = *buf; > > tmp_line[chptr++] = *buf; > if (*buf == 10 || *buf == 13) { > tmp_line[chptr] = '\0'; > chptr = 0; > if (!strncasecmp(tmp_line, "Location: ", 10)) { > tpath = tmp_line + 10; > strcpy(location, tpath); > } > } > if (lineone && (*buf == 10 || *buf == 13)) { > lineone = 0; > } > if (lineone && oldch5 == ' ' && oldch4 == '2' > && oldch3 == '0' > && > oldch2 == '0' && oldch1 == ' ') { > reqok = 1; > } > if (oldch4 == 13 && oldch3 == 10 && oldch2 == 13 && oldch1 > == > 10) { > body = 1; > } > if (oldch2 == 10 && oldch1 == 10) { > body = 1; > } > if (oldch2 == 13 && oldch1 == 13) { > body = 1; > } > } > -- PHP Development Mailing List http://www.php.net/ To unsubscribe send an empty message to php-dev-unsubscribe@lists.php.net For help: php-dev-help@lists.php.net

« previous php.dev (#6011) next »