Bug #13107 Updated: php_ini.c:197 coding bug
| From: | rasmus@php.net | Date: | Mon, 03 Sep 2001 15:36:44 +0000 |
| Subject: | Bug #13107 Updated: php_ini.c:197 coding bug | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-64973@lists.php.net to get a copy of this message | ||
ID: 13107
Updated by: rasmus
Reported By: nick@macaw.demon.co.uk
Old Status: Open
Status: Closed
Bug Type: Scripting Engine problem
Operating System: All
PHP Version: 4.0.6
New Comment:
Fixed - good catch
Previous Comments:
------------------------------------------------------------------------
[2001-09-03 08:01:14] nick@macaw.demon.co.uk
Probably should be sizeof(char*) rather than sizeof(zval) here as zend extension paths are stored as
a strings rather than zvals, as below. As a result the stack is blown on the resultant memcpy in the
llist code.
zend_llist_init(&extension_lists.engine, sizeof(zval), (llist_dtor_func_t) free_estring, 1);
/*...*/
char *extension_name = estrndup(Z_STRVAL_P(arg2), Z_STRLEN_P(arg2));
zend_llist_add_element(&extension_lists.engine, &extension_name);
------------------------------------------------------------------------
Edit this bug report at http://bugs.php.net/?id=13107&edit=1