|
php.net | support | documentation | report a bug | advanced search | search howto | statistics | random bug | login |
PatchesPull RequestsHistoryAllCommentsChangesGit/SVN commits
[2000-12-28 05:53 UTC] sniper@php.net
|
|||||||||||||||||||||||||||
Copyright © 2001-2026 The PHP GroupAll rights reserved. |
Last updated: Sat Oct 10 11:00:01 2026 UTC |
This bug was triggered by a bad call from xml_call_handler. call_user_function_ex takes a void** pointer from the caller and doubly dereferences the pointer in the macro call Z_TYPE_PP on line 365 of zend_execute_API.c I suggest the following change to make zend_execute_API.c crash safe. diff -c -r1.1.1.1 zend_execute_API.c *** zend_execute_API.c 2000/12/22 00:13:44 1.1.1.1 --- zend_execute_API.c 2000/12/22 19:30:46 *************** *** 362,368 **** } if (object_pp) { ! if (Z_TYPE_PP(object_pp) != IS_OBJECT) { return FAILURE; } function_table = &(*object_pp)->value.obj.ce->function_table; --- 362,368 ---- } if (object_pp) { ! if (!*object_pp || Z_TYPE_PP(object_pp) != IS_OBJECT) { return FAILURE; } function_table = &(*object_pp)->value.obj.ce->function_table; In addition, to fix the real problem the following change to xml.c diff -r1.1.1.1 xml.c 361c361 < result = call_user_function(EG(function_table), &parser->object, handler, retval, argc, argv); --- > result = call_user_function(EG(function_table), parser->object ? &parser->object : NULL, handler, retval, argc, argv); :lou http://montulli.org/lou/