Re: bug in php3_imap_reopen

From: Date: Thu, 01 Jan 1970 00:00:00 +0000
Subject: Re: bug in php3_imap_reopen
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-9990@lists.php.net to get a copy of this message
Hi A week ago I sent a mail about a bug in imap_reopen in PHP3 and I haven't really gotten any reply. The problem is that reopen does the following: imap_stream = mail_open(imap_le_struct->imap_stream, mailbox->value.str. val, flags); if (imap_stream == NIL) { php3_error(E_WARNING,"Couldn't re-open stream\n"); RETURN_FALSE; } RETURN_TRUE; but if mail_open fails to reopen, mail_open frees the memory that imap_stream points to, allocates some new and returns a pointer to that. The new value is ignored by imap_reopen. The result is typically a seg fault when some imap function later on tries to use the stream and accesses the freed memory. The fix is simply to add the following line right after the call to mail_open: imap_le_struct->imap_stream = imap_stream; In most cases this won't be needed but I prefer to always do this rather than first check if they are equal. May I fix this in the CVS tree please? If you need more details please look at my previous posting or ask me. Stig

« previous php.dev (#9990) next »