CVS update: php3/functions

From: Date: Mon, 28 Jun 1999 08:40:59 +0000
Subject: CVS update: php3/functions
Groups: php.dev 
Request: Send a blank email to php-dev+get-7672@lists.php.net to get a copy of this message
Date: Monday June 28, 1999 @ 4:40 Author: bjh Update of /repository/php3/functions In directory php:/tmp/cvs-serv5697 Modified Files: crypt.c Log Message: Stop core dump using crypt() with standard DES. When PHP3_MAX_SALT_LEN = 2 adding the null terminator to the salt exceeds allocated space causing stack corruption. Index: php3/functions/crypt.c diff -u php3/functions/crypt.c:1.47 php3/functions/crypt.c:1.48 --- php3/functions/crypt.c:1.47 Tue Jun 22 06:17:41 1999 +++ php3/functions/crypt.c Mon Jun 28 04:40:59 1999 @@ -28,7 +28,7 @@ | Rasmus Lerdorf <rasmus@lerdorf.on.ca> | +----------------------------------------------------------------------+ */ -/* $Id: crypt.c,v 1.47 1999/06/22 10:17:41 sas Exp $ */ +/* $Id: crypt.c,v 1.48 1999/06/28 08:40:59 bjh Exp $ */ #include <stdlib.h> #include "php.h" @@ -130,7 +130,7 @@ Encrypt a string */ void php3_crypt(INTERNAL_FUNCTION_PARAMETERS) { - char salt[PHP3_MAX_SALT_LEN]; + char salt[PHP3_MAX_SALT_LEN+1]; pval *arg1, *arg2; salt[0]='\0';

« previous php.dev (#7672) next »