php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #8381 Crash in call_user_function_ex
Submitted: 2000-12-22 14:32 UTC Modified: 2000-12-28 05:53 UTC
From: lou at montulli dot org Assigned:
Status: Closed Package: Reproducible Crash
PHP Version: 4.0.4 OS: linux
Private report: No CVE-ID: None
 [2000-12-22 14:32 UTC] lou at montulli dot org
This bug was triggered by a bad call from xml_call_handler.

call_user_function_ex takes a void** pointer from the caller and doubly dereferences the pointer in the macro call Z_TYPE_PP on line 365 of zend_execute_API.c

I suggest the following change to make zend_execute_API.c crash safe.

diff -c -r1.1.1.1 zend_execute_API.c
*** zend_execute_API.c	2000/12/22 00:13:44	1.1.1.1
--- zend_execute_API.c	2000/12/22 19:30:46
***************
*** 362,368 ****
  	}
  
  	if (object_pp) {
! 		if (Z_TYPE_PP(object_pp) != IS_OBJECT) {
  			return FAILURE;
  		}
  		function_table = &(*object_pp)->value.obj.ce->function_table;
--- 362,368 ----
  	}
  
  	if (object_pp) {
! 		if (!*object_pp || Z_TYPE_PP(object_pp) != IS_OBJECT) {
  			return FAILURE;
  		}
  		function_table = &(*object_pp)->value.obj.ce->function_table;


In addition, to fix the real problem the following change to xml.c 

diff -r1.1.1.1 xml.c
361c361
< 		result = call_user_function(EG(function_table), &parser->object, handler, retval, argc, argv);
---
> 		result = call_user_function(EG(function_table), parser->object ? &parser->object : NULL, handler, retval, argc, argv);

:lou
http://montulli.org/lou/

Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2000-12-28 05:53 UTC] sniper@php.net
AFAIK, this should be fixed in CVs.
Please try the latest snapshot from http://snaps.php.net/
and reopen this bug report if problem still exists.

--Jani
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Sat Oct 10 10:00:02 2026 UTC