Re: Ack, #1449 is real
| From: | Stig Bakken | Date: | Wed, 26 May 1999 09:49:54 +0000 |
| Subject: | Re: Ack, #1449 is real | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-6011@lists.php.net to get a copy of this message | ||
This stopped as of the final 3.0.8 release. It should not have crept into
3.0.8 :-P. I didn't get time to test Sascha's new code before it was
released, but yesterday I found exactly the same bug on Solaris. Looking
into it. We probably need to release 3.0.9 pretty soon.
- Stig
On Tue, 25 May 1999, Rasmus Lerdorf wrote:
> Yeah, we are writing madly into memory in the new socket code.
>
> This loop in fopen_wrappers.c starting at line 592 overflows the 256 char
> tmp_line variable. chptr happily goes well past that, and I don't see any
> sort of check that would attempt to stop it from doing so.
>
> Stig, am I missing something here? I believe this is your code.
> Obviously the assumption here is that a set of response headers will never
> contain a line longer than 256 chars and that each line will be terminated
> by a \r a \n or a \r\n and although this appears to be a valid assumption,
> for some reason *buf keeps ending up '\0' when I step through this and as
> such this loops forever. So, although the problem isn't likely here, I
> think this is where we blow away the stack. Adding a check to the while
> condition there and having the loop terminate if chptr goes above 256
> makes the segfault go away, but since SOCK_FGETC returned nothing but \0's
> the returned array from the file() call is obviously bogus. The question
> is why isn't SOCK_FGETC() working?
>
> while (!body && !SOCK_FEOF(*socketd)) {
> if (SOCK_FGETC(*socketd) == SOCK_RECV_ERR) {
> SOCK_FCLOSE(*socketd);
> *socketd = 0;
> free_url(resource);
> return NULL;
> }
> oldch5 = oldch4;
> oldch4 = oldch3;
> oldch3 = oldch2;
> oldch2 = oldch1;
> oldch1 = *buf;
>
> tmp_line[chptr++] = *buf;
> if (*buf == 10 || *buf == 13) {
> tmp_line[chptr] = '\0';
> chptr = 0;
> if (!strncasecmp(tmp_line, "Location: ", 10)) {
> tpath = tmp_line + 10;
> strcpy(location, tpath);
> }
> }
> if (lineone && (*buf == 10 || *buf == 13)) {
> lineone = 0;
> }
> if (lineone && oldch5 == ' ' && oldch4 == '2'
> && oldch3 == '0'
> &&
> oldch2 == '0' && oldch1 == ' ') {
> reqok = 1;
> }
> if (oldch4 == 13 && oldch3 == 10 && oldch2 == 13 && oldch1
> ==
> 10) {
> body = 1;
> }
> if (oldch2 == 10 && oldch1 == 10) {
> body = 1;
> }
> if (oldch2 == 13 && oldch1 == 13) {
> body = 1;
> }
> }
>
--
PHP Development Mailing List http://www.php.net/
To unsubscribe send an empty message to php-dev-unsubscribe@lists.php.net
For help: php-dev-help@lists.php.net