[PATCH] patch for design violation in SAPI.c
| From: | Martin Jahn | Date: | Thu, 27 Sep 2001 08:14:40 +0000 |
| Subject: | [PATCH] patch for design violation in SAPI.c | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-66715@lists.php.net to get a copy of this message | ||
hello,
i think i have a patch that should made it into your next release
candidate before the problem is forgoten:
the function sapi_module.read_cookies does return a pointer that is allocated within the addresspace of the server (f.e. apache). this
is a violation of the idea behind modular programming.
the cookie_data should be properly estrduped to ensure, that
whatever a php extension does with the cookie_data it never
ever touches addresspace that was not allocated by php itself.
the patch i send you with this mail does exactly this:
1) estrdup cookie_data if != NULL
2) efree it on exit
martin
Attachment: [application/octet-stream] SAPI.diff
Attachment: [application/octet-stream] SAPI.diff