imap_mime_header_decode segfaults
| From: | Jade Nicoletti | Date: | Wed, 10 May 2000 09:08:46 +0000 |
| Subject: | imap_mime_header_decode segfaults | ||
| Groups: | php.version4 | ||
| Request: | Send a blank email to php-version4+get-14717@lists.php.net to get a copy of this message | ||
Hi,
A qprint encoded string beginning with an encoded char (for example
'=?ISO-8859-1?q?=e4?=') causes php to segfault.
The bugfix is appended.
BTW this function doesn't do any sanity checks, so that invalid mime headers
may still crash php (for example '=?ISO-8859-1?=e4?='). Sorry, I don't have
the time to fix this.
-Jade.
--
===============================================================================
Jade Nicoletti Nicoletti Net Services Tel. 01 240 4774
Geschäftsleitung Postfach 2519 Fax 01 240 4775
System-Administration 8021 Zürich
============================================[ Weitere Infos: http://nns.ch/ ]==
--- php_imap.c.orig Wed May 10 10:54:58 2000 +++ php_imap.c Wed May 10 10:54:11 2000 @@ -3461,7 +3461,7 @@ } if ((encoding_token=(long) php_memnstr(&string[charset_token+2], "?", 1, string+end))) { /* Find token for encoding */ encoding_token -= (long) string; - if ((end_token=(long) php_memnstr(&string[encoding_token+1], "?=", 2, string+end))) { /* Find token for end of encoded data */ + if ((end_token=(long) php_memnstr(&string[encoding_token+3], "?=", 2, string+end))) { /* Find token for end of encoded data */ end_token -= (long) string; memcpy(charset, &string[charset_token+2], encoding_token-(charset_token+2)); /* Extract charset encoding */ charset[encoding_token-(charset_token+2)]=0x00;
--- php_imap.c.orig Wed May 10 10:54:58 2000 +++ php_imap.c Wed May 10 10:54:11 2000 @@ -3461,7 +3461,7 @@ } if ((encoding_token=(long) php_memnstr(&string[charset_token+2], "?", 1, string+end))) { /* Find token for encoding */ encoding_token -= (long) string; - if ((end_token=(long) php_memnstr(&string[encoding_token+1], "?=", 2, string+end))) { /* Find token for end of encoded data */ + if ((end_token=(long) php_memnstr(&string[encoding_token+3], "?=", 2, string+end))) { /* Find token for end of encoded data */ end_token -= (long) string; memcpy(charset, &string[charset_token+2], encoding_token-(charset_token+2)); /* Extract charset encoding */ charset[encoding_token-(charset_token+2)]=0x00;