php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #7577 Reporducable curl_exec() segfault
Submitted: 2000-11-01 18:08 UTC Modified: 2000-11-05 11:25 UTC
From: torben@php.net Assigned:
Status: Closed Package: Reproducible Crash
PHP Version: 4.0 Latest CVS (01/11/2000) OS: Mandrake 7.0
Private report: No CVE-ID: None
 [2000-11-01 18:08 UTC] torben@php.net
An empty value in the array given to curl_setopt() with 
CURLOPT_QUOTE or CURLOPT_POSTQUOTE causes PHP to segfault
in the curl library:

<?php /* -*- mode: c++; minor-mode: font -*- */ 
error_reporting(E_ALL);
$url = 'ftp://ftp.thebuttlesschaps.com';
$userpwd = 'thebuttl:*******';

/* Contrived for illustration. */
$ftp_quote = array('cwd htdocs', false, 'cwd /');

$curld = curl_init();
curl_setopt($curld, CURLOPT_URL, $url);
curl_setopt($curld, CURLOPT_USERPWD, $userpwd);
curl_setopt($curld, CURLOPT_QUOTE, $ftp_quote);
curl_setopt($curld, CURLOPT_VERBOSE, true);
curl_exec($curld);
curl_close($curld);
?>

Backtrace:

~/work/php4
shanna% gdb ./php                                         
GNU gdb 19991116
Copyright 1998 Free Software Foundation, Inc.
GDB is free software, covered by the GNU General Public License, and you are
welcome to change it and/or distribute copies of it under certain conditions.
Type "show copying" to see the conditions.
There is absolutely no warranty for GDB.  Type "show warranty" for details.
This GDB was configured as "i586-mandrake-linux"...
(gdb) run -q ~/public_html/php3test/curlcrash.html
Starting program: /home/www/work/php4/./php -q ~/public_html/php3test/curlcrash.html
< 220 ftp2.hostme.com FTP server (Version wu-2.6.0(1) Tue Jul 11 20:31:53 EDT 2000) ready.
> USER thebuttl
< 331 Password required for thebuttl.
> PASS ********
< 230-Please read the file README
< 230-  it was last modified on Fri May  7 19:39:51 1999 - 544 days ago
< 230 User thebuttl logged in.
* We have successfully logged in
* Connected to ftp.thebuttlesschaps.com (206.245.164.13)

Program received signal SIGSEGV, Segmentation fault.
0x4014aefa in mvaprintf (format=0x4014e9e6 "%s", ap_save=0xbfffa0e0) at mprintf.c:1151
1151      info.buffer[info.len] = 0; /* we terminate this with a zero byte */
(gdb) bt
#0  0x4014aefa in mvaprintf (format=0x4014e9e6 "%s", ap_save=0xbfffa0e0) at mprintf.c:1151
#1  0x40142121 in ftpsendf (fd=7, conn=0x81d11b0, fmt=0x4014e9e6 "%s") at sendf.c:133
#2  0x40142eca in _ftp (conn=0x81d11b0) at ftp.c:628
#3  0x40144553 in ftp (conn=0x81d11b0) at ftp.c:1420
#4  0x401472e0 in curl_do (in_conn=0x81d11b0) at url.c:1516
#5  0x4014d98c in curl_transfer (curl=0x81d6268) at highlevel.c:629
#6  0x4014dd6b in curl_easy_perform (curl=0x81d6268) at easy.c:157
#7  0x806b38f in php_if_curl_exec (ht=1, return_value=0x81d6064, this_ptr=0x0, 
    return_value_used=0) at curl.c:597
#8  0x810baef in execute (op_array=0x81d109c) at ./zend_execute.c:1519
#9  0x80e3f5b in zend_execute_scripts (type=8, file_count=3) at zend.c:717
#10 0x80639f4 in php_execute_script (primary_file=0xbffff9c8) at main.c:1210
#11 0x8062004 in main (argc=3, argv=0xbffffa44) at cgi_main.c:725
(gdb) quit


This patch seems to fix it:

Index: curl.c
===================================================================
RCS file: /repository/php4/ext/curl/curl.c,v
retrieving revision 1.21
diff -u -r1.21 curl.c
--- curl.c	2000/10/27 19:10:21	1.21
+++ curl.c	2000/11/01 22:41:25
@@ -533,6 +533,10 @@
 					
 					SEPARATE_ZVAL(current);
 					convert_to_string_ex(current);
+
+                    if (Z_STRLEN_PP(current) < 1) {
+                        continue;
+                    }
 					
 					indiv_command = estrndup(Z_STRVAL_PP(current), Z_STRLEN_PP(current));
 					commands = curl_slist_append(commands, indiv_command);


Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2000-11-05 11:25 UTC] stas@php.net
Commited to CVS. Please check.
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Sun Oct 11 19:00:02 2026 UTC