Bug #14046 Updated: segfaults due to curlopt not checking file handles are valid
| From: | sterling@php.net | Date: | Tue, 20 Nov 2001 10:59:09 +0000 |
| Subject: | Bug #14046 Updated: segfaults due to curlopt not checking file handles are valid | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-71048@lists.php.net to get a copy of this message | ||
ID: 14046
Updated by: sterling
Reported By: alan_k@hklc.com
Old Status: Assigned
Status: Closed
Bug Type: cURL related
Operating System: debian linux
PHP Version: 4.0CVS-2001-11-13
Assigned To: sterling
New Comment:
RETURN_FALSE; is enough, since ZEND_FETCH_RESOURCE() will complain with an E_WARNING... Will modify
source, in next commit with POSTFIELDS commit...
Previous Comments:
------------------------------------------------------------------------
[2001-11-14 02:25:21] derick@php.net
Assigned this to you sterling, cause you're the cURL master here.
Derick
------------------------------------------------------------------------
[2001-11-13 21:20:07] alan_k@hklc.com
curlopt does not check that file handles are valid - so if you send it a string for CURL_INFILE it
will segfault.
patch below
Index: curl.c
===================================================================
RCS file: /repository/php4/ext/curl/curl.c,v
retrieving revision 1.97
diff -u -r1.97 curl.c
--- curl.c 13 Nov 2001 11:47:52 -0000 1.97
+++ curl.c 14 Nov 2001 02:16:47 -0000
@@ -706,8 +706,13 @@
case CURLOPT_INFILE:
case CURLOPT_WRITEHEADER:
case CURLOPT_STDERR: {
- FILE *fp;
+ FILE *fp=NULL;
ZEND_FETCH_RESOURCE(fp, FILE *, zvalue, -1, "File-Handle",
php_file_le_fopen());
+ if (!fp) {
+ php_error(E_WARNING, "You must pass a file handle with the
CURLOPT_FILE,"
+ "CURLOPT_INFILE, CURLOPT_WRITEHEADER and
CURLOPT_STDERR arguments");
+ RETURN_FALSE;
+ }
error = CURLE_OK;
switch (option) {
------------------------------------------------------------------------
Edit this bug report at http://bugs.php.net/?id=14046&edit=1