CVS update: php3

From: Date: Tue, 22 Jun 1999 02:06:21 +0000
Subject: CVS update: php3
Groups: php.dev 
Request: Send a blank email to php-dev+get-7378@lists.php.net to get a copy of this message
Date: Monday June 21, 1999 @ 22:06 Author: ssb Update of /repository/php3 In directory php:/tmp/cvs-serv5932 Modified Files: fopen-wrappers.c Log Message: fix some potential buffer overflows Index: php3/fopen-wrappers.c diff -u php3/fopen-wrappers.c:1.66 php3/fopen-wrappers.c:1.67 --- php3/fopen-wrappers.c:1.66 Fri Jun 18 10:44:17 1999 +++ php3/fopen-wrappers.c Mon Jun 21 22:06:21 1999 @@ -27,7 +27,7 @@ | Jim Winstead <jimw@php.net> | +----------------------------------------------------------------------+ */ -/* $Id: fopen-wrappers.c,v 1.66 1999/06/18 14:44:17 ssb Exp $ */ +/* $Id: fopen-wrappers.c,v 1.67 1999/06/22 02:06:21 ssb Exp $ */ #ifdef THREAD_SAFE #include "tls.h" @@ -468,7 +468,7 @@ char *tpath, *ttpath; int body = 0; int reqok = 0; - int i; + int i, len; FILE *fp = NULL; struct sockaddr_in server; @@ -522,22 +522,26 @@ #endif /*win32 */ strcpy(hdr_line, "GET "); + len = 4; /* tell remote http which file to get */ if (resource->path != NULL) { - strncat(hdr_line, resource->path, sizeof(hdr_line)); + strncat(hdr_line, resource->path, sizeof(hdr_line)-len); + len += strlen(resource->path); } else { - strncat(hdr_line, "/", sizeof(hdr_line)); + strncat(hdr_line, "/", sizeof(hdr_line)-len); + len++; } - /* append the query string, if any */ if (resource->query != NULL) { - strncat(hdr_line, "?", sizeof(hdr_line)); - strncat(hdr_line, resource->query, sizeof(hdr_line)); + strncat(hdr_line, "?", sizeof(hdr_line)-len); + len++; + strncat(hdr_line, resource->query, sizeof(hdr_line)-len); + len += strlen(resource->query); } - strncat(hdr_line, " HTTP/1.0\r\n", sizeof(hdr_line)); + strncat(hdr_line, " HTTP/1.0\r\n", sizeof(hdr_line)-len); hdr_line[sizeof(hdr_line)-1] = '\0'; SOCK_WRITE(hdr_line, *socketd); - + /* send authorization header if we have user/pass */ if (resource->user != NULL && resource->pass != NULL) { scratch = (char *) emalloc(strlen(resource->user) + strlen(resource->pass) + 2); @@ -550,49 +554,43 @@ strcat(scratch, resource->pass); tmp = _php3_base64_encode((unsigned char *)scratch, strlen(scratch), NULL); - strcpy(hdr_line, "Authorization: Basic "); - /* output "user:pass" as base64-encoded string */ - strncat(hdr_line, (char *)tmp, sizeof(hdr_line)); - strncat(hdr_line, "\r\n", sizeof(hdr_line)); - hdr_line[sizeof(hdr_line)-1] = '\0'; - SOCK_WRITE(hdr_line, *socketd); + if (snprintf(hdr_line, sizeof(hdr_line), + "Authorization: Basic %s\r\n", tmp) > 0) { + SOCK_WRITE(hdr_line, *socketd); + } + efree(scratch); efree(tmp); } /* if the user has configured who they are, send a From: line */ if (cfg_get_string("from", &scratch) == SUCCESS) { - strcpy(hdr_line, "From: "); - strncat(hdr_line, scratch, sizeof(hdr_line)); - strncat(hdr_line, "\r\n", sizeof(hdr_line)); - hdr_line[sizeof(hdr_line)-1] = '\0'; - SOCK_WRITE(hdr_line, *socketd); + if (snprintf(hdr_line, sizeof(hdr_line), + "From: %s\r\n", scratch) > 0) { + SOCK_WRITE(hdr_line, *socketd); + } } /* send a Host: header so name-based virtual hosts work */ - strcpy(hdr_line, "Host: "); - strncat(hdr_line, resource->host, sizeof(hdr_line)); if (resource->port != 80) { - sprintf(tmp_line, "%i", resource->port); - strncat(hdr_line, ":", sizeof(hdr_line)); - strncat(hdr_line, tmp_line, sizeof(hdr_line)); + len = snprintf(hdr_line, sizeof(hdr_line), + "Host: %s:%i\r\n", resource->host, resource->port); + } else { + len = snprintf(hdr_line, sizeof(hdr_line), + "Host: %s\r\n", resource->host); } - strncat(hdr_line, "\r\n", sizeof(hdr_line)); - hdr_line[sizeof(hdr_line)-1] = '\0'; - SOCK_WRITE(hdr_line, *socketd); + if (len > 0) { + SOCK_WRITE(hdr_line, *socketd); + } /* identify ourselves and end the headers */ - strcpy(hdr_line, "User-Agent: PHP/"); - strncat(hdr_line, PHP_VERSION, sizeof(hdr_line)); - strncat(hdr_line, "\r\n\r\n", sizeof(hdr_line)); - hdr_line[sizeof(hdr_line)-1] = '\0'; - SOCK_WRITE(hdr_line, *socketd); + SOCK_WRITE("User-Agent: PHP/" PHP_VERSION "\r\n\r\n", *socketd); body = 0; location[0] = '\0'; if (!SOCK_FEOF(*socketd)) { /* get response header */ if (SOCK_FGETS(tmp_line, sizeof(tmp_line), *socketd) != NULL) { - if (!strncmp(tmp_line + 8, " 200 ", 4)) { + if (strncmp(tmp_line + 8, " 200 ", 5) == NULL) { reqok = 1; } }

« previous php.dev (#7378) next »