nlopess         Sat Sep 16 18:15:25 2006 UTC

  Modified files:              (Branch: PHP_5_2)
    /php-src/ext/xmlreader      php_xmlreader.c 
    /php-src/ext/xmlwriter      php_xmlwriter.c 
  Log:
  add missing checks around expand_filepath()
  
http://cvs.php.net/viewvc.cgi/php-src/ext/xmlreader/php_xmlreader.c?r1=1.13.2.14.2.2&r2=1.13.2.14.2.3&diff_format=u
Index: php-src/ext/xmlreader/php_xmlreader.c
diff -u php-src/ext/xmlreader/php_xmlreader.c:1.13.2.14.2.2 
php-src/ext/xmlreader/php_xmlreader.c:1.13.2.14.2.3
--- php-src/ext/xmlreader/php_xmlreader.c:1.13.2.14.2.2 Tue Jun  6 21:44:34 2006
+++ php-src/ext/xmlreader/php_xmlreader.c       Sat Sep 16 18:15:25 2006
@@ -16,7 +16,7 @@
   +----------------------------------------------------------------------+
 */
 
-/* $Id: php_xmlreader.c,v 1.13.2.14.2.2 2006/06/06 21:44:34 tony2001 Exp $ */
+/* $Id: php_xmlreader.c,v 1.13.2.14.2.3 2006/09/16 18:15:25 nlopess Exp $ */
 
 #ifdef HAVE_CONFIG_H
 #include "config.h"
@@ -260,9 +260,8 @@
        file_dest = source;
 
        if ((uri->scheme == NULL || isFileUri)) {
-               /* XXX possible buffer overflow if VCWD_REALPATH does not know 
size of resolved_path */
-               if (! VCWD_REALPATH(source, resolved_path)) {
-                       expand_filepath(source, resolved_path TSRMLS_CC);
+               if (!VCWD_REALPATH(source, resolved_path) && 
!expand_filepath(source, resolved_path TSRMLS_CC)) {
+                       return NULL;
                }
                file_dest = resolved_path;
        }
http://cvs.php.net/viewvc.cgi/php-src/ext/xmlwriter/php_xmlwriter.c?r1=1.20.2.12.2.3&r2=1.20.2.12.2.4&diff_format=u
Index: php-src/ext/xmlwriter/php_xmlwriter.c
diff -u php-src/ext/xmlwriter/php_xmlwriter.c:1.20.2.12.2.3 
php-src/ext/xmlwriter/php_xmlwriter.c:1.20.2.12.2.4
--- php-src/ext/xmlwriter/php_xmlwriter.c:1.20.2.12.2.3 Tue Jul 11 16:33:25 2006
+++ php-src/ext/xmlwriter/php_xmlwriter.c       Sat Sep 16 18:15:25 2006
@@ -17,7 +17,7 @@
   +----------------------------------------------------------------------+
 */
 
-/* $Id: php_xmlwriter.c,v 1.20.2.12.2.3 2006/07/11 16:33:25 tony2001 Exp $ */
+/* $Id: php_xmlwriter.c,v 1.20.2.12.2.4 2006/09/16 18:15:25 nlopess Exp $ */
 
 #ifdef HAVE_CONFIG_H
 #include "config.h"
@@ -272,9 +272,8 @@
        file_dest = source;
 
        if ((uri->scheme == NULL || isFileUri)) {
-               /* XXX possible buffer overflow if VCWD_REALPATH does not know 
size of resolved_path */
-               if (! VCWD_REALPATH(source, resolved_path)) {
-                       expand_filepath(source, resolved_path TSRMLS_CC);
+               if (!VCWD_REALPATH(source, resolved_path) && 
!expand_filepath(source, resolved_path TSRMLS_CC)) {
+                       return NULL;
                }
                file_dest = resolved_path;
        }

-- 
PHP CVS Mailing List (http://www.php.net/)
To unsubscribe, visit: http://www.php.net/unsub.php

Reply via email to