php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #8381 Crash in call_user_function_ex
Submitted: 2000-12-22 14:32 UTC Modified: 2000-12-28 05:53 UTC
From: lou at montulli dot org Assigned:
Status: Closed Package: Reproducible Crash
PHP Version: 4.0.4 OS: linux
Private report: No CVE-ID: None
Welcome back! If you're the original bug submitter, here's where you can edit the bug or add additional notes.
If you forgot your password, you can retrieve your password here.
Password:
Status:
Package:
Bug Type:
Summary:
From: lou at montulli dot org
New email:
PHP Version: OS:

 

 [2000-12-22 14:32 UTC] lou at montulli dot org
This bug was triggered by a bad call from xml_call_handler.

call_user_function_ex takes a void** pointer from the caller and doubly dereferences the pointer in the macro call Z_TYPE_PP on line 365 of zend_execute_API.c

I suggest the following change to make zend_execute_API.c crash safe.

diff -c -r1.1.1.1 zend_execute_API.c
*** zend_execute_API.c	2000/12/22 00:13:44	1.1.1.1
--- zend_execute_API.c	2000/12/22 19:30:46
***************
*** 362,368 ****
  	}
  
  	if (object_pp) {
! 		if (Z_TYPE_PP(object_pp) != IS_OBJECT) {
  			return FAILURE;
  		}
  		function_table = &(*object_pp)->value.obj.ce->function_table;
--- 362,368 ----
  	}
  
  	if (object_pp) {
! 		if (!*object_pp || Z_TYPE_PP(object_pp) != IS_OBJECT) {
  			return FAILURE;
  		}
  		function_table = &(*object_pp)->value.obj.ce->function_table;


In addition, to fix the real problem the following change to xml.c 

diff -r1.1.1.1 xml.c
361c361
< 		result = call_user_function(EG(function_table), &parser->object, handler, retval, argc, argv);
---
> 		result = call_user_function(EG(function_table), parser->object ? &parser->object : NULL, handler, retval, argc, argv);

:lou
http://montulli.org/lou/

Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2000-12-28 05:53 UTC] sniper@php.net
AFAIK, this should be fixed in CVs.
Please try the latest snapshot from http://snaps.php.net/
and reopen this bug report if problem still exists.

--Jani
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Sat Oct 10 11:00:01 2026 UTC