php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #31684 dio_tcsetattr implementation leads to misconfigured termios settings
Submitted: 2005-01-25 04:38 UTC Modified: 2005-01-25 14:43 UTC
From: elod at itfais dot com Assigned:
Status: Closed Package: Filesystem function related
PHP Version: 4.3.10 OS: MacOSX 10.3.7
Private report: No CVE-ID:
 [2005-01-25 04:38 UTC] elod at itfais dot com
Description:
------------
The implementation of dio_tcsetattr misuses the 
tcsetattr() function call for setting termios parameters 
on a descriptor.  It fills an uninitialized stack local 
termios structure with parameters gleened from input to 
the dio_tcsetattr() function call while leaving all 
other paramters uninitialized.  This can (and does) lead 
to unpredictable behavior on the device when default 
settings are overwritten with garbage.  

The correct way to set termio structure information is 
to first _get_ the current termios settings 
(tcgetattr) on the device, then modifying only the flags 
necessary, and then setting the modified termios with 
tcsetattr().

Following is a diff of ext/dio.c between the 
distribution version and my modified (and fixed) 
version:

598a599,600
>       memset(&newtio, 0, sizeof(newtio));
>       tcgetattr(f->fd, &newtio);


Patches

Add a Patch

Pull Requests

Add a Pull Request

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2005-01-25 14:43 UTC] sniper@php.net
This bug has been fixed in CVS.

Snapshots of the sources are packaged every three hours; this change
will be in the next snapshot. You can grab the snapshot at
http://snaps.php.net/.
 
Thank you for the report, and for helping us make PHP better.


 
PHP Copyright © 2001-2014 The PHP Group
All rights reserved.
Last updated: Sun Apr 20 15:01:54 2014 UTC