Bug #10447 Updated: ccvs_*() functions segfault when given invalid session ID

From: Date: Mon, 23 Jul 2001 15:37:35 +0000
Subject: Bug #10447 Updated: ccvs_*() functions segfault when given invalid session ID
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-60768@lists.php.net to get a copy of this message
ID: 10447 Updated by: bmcadams Reported By: torben@php.net Status: Assigned Bug Type: CCVS related Operating System: Linux Mandrake 7.0 PHP Version: 4.0 Latest CVS (22/04/2001) Assigned To: bmcadams@php.net New Comment: This issue is still outstanding. FTR, the people at RedHat who wrote this code (Originally HKS Systems) were all laid off, and the project was assigned to the newly acquired 'Stronghold' division; none of whom have a clue about the CCVS Code. They are more or less telling me it's our responsibility to preven the user from passing a bad session. Anyone got any bright ideas on easy ways to track if a session being passed in was one created during this session of PHP? ... Previous Comments: ------------------------------------------------------------------------ [2001-04-22 20:38:14] bmcadams@php.net The fix that sterling put in place will at the least check if the session being passed is a string value: this still doesn't protect from someone arbitrarily passing any old string (for example "crash_ccvs"). While obviously it is up to the programmer to be smart and not pass a bad session to CCVS, CCVS Should not be segfaulting if they pass a bad value. I am looking into a way to trap this value from being bad. ------------------------------------------------------------------------ [2001-04-22 20:29:54] torben@php.net No, he didn't. :) The problem itself is that session IDs are completely exposed (i.e. not resource- or list-based) and there is no error-checking in the module. The check that was added didn't help; the same code still segfaults and all of the other affected functions are still affected. ------------------------------------------------------------------------ [2001-04-22 20:21:19] jmoore@php.net Sterling fixed this in CVS. - James ------------------------------------------------------------------------ [2001-04-22 20:17:11] bmcadams@php.net I have duplicated this issue on my end and I am looking into it. Fix imminent. ------------------------------------------------------------------------ [2001-04-22 19:37:22] torben@php.net The ccvs functions segfault when given an invalid session ID. This works fine: <?php $session = ccvs_init('ccvs'); echo "Adding an invoice to the session:\n"; if (!ccvs_new($session, 'foo') === 'OK') { echo "Could not create invoice; reason: " . ccvs_textvalue($session) . "\n"; } ?> This segfaults: <?php $session = ccvs_init('ccvs'); echo "Adding an invoice to the session:\n"; if (!ccvs_new($sess, 'foo') === 'OK') { echo "Could not create invoice; reason: " . ccvs_textvalue($session) . "\n"; } ?> Backtrace: /home/www/php shanna% gdb php GNU gdb 19991116 Copyright 1998 Free Software Foundation, Inc. GDB is free software, covered by the GNU General Public License, and you are welcome to change it and/or distribute copies of it under certain conditions. Type "show copying" to see the conditions. There is absolutely no warranty for GDB. Type "show warranty" for details. This GDB was configured as "i586-mandrake-linux"... (gdb) run ./ccvstest Starting program: /usr/local/bin/php ./ccvstest X-Powered-By: PHP/4.0.6-dev Content-type: text/html Trying a presumably invalid configuration: Returned: ''; Return type: string Trying a presumably valid configuration: Adding an invoice to the session: Looking up the new invoice: PHP Warning: Undefined variable: sssion in ./ccvstest on line 17 <br> <b>Warning</b>: Undefined variable: sssion in <b>./ccvstest</b> on line <b>17</b><br> ./ccvstest(17) : Warning - Undefined variable: sssion Program received signal SIGSEGV, Segmentation fault. 0x4024b791 in strlen () from /lib/libc.so.6 (gdb) bt #0 0x4024b791 in strlen () from /lib/libc.so.6 #1 0x8071a0d in php_if_ccvs_lookup (ht=3, return_value=0x831164c, this_ptr=0x0, return_value_used=1) at ccvs.c:486 #2 0x8171cba in execute (op_array=0x82f5a3c) at ./zend_execute.c:1494 #3 0x8138084 in zend_execute_scripts (type=8, file_count=3) at zend.c:743 #4 0x806a27f in php_execute_script (primary_file=0xbffff924) at main.c:1196 #5 0x806825c in main (argc=2, argv=0xbffff9b4) at cgi_main.c:735 (gdb) ------------------------------------------------------------------------ Edit this bug report at http://bugs.php.net/?id=10447&edit=1

« previous php.dev (#60768) next »