af9dc8
From 7d163e8a0880ae8af2dd869071393e5dc07ef271 Mon Sep 17 00:00:00 2001
af9dc8
From: Rob Richards <rrichards@php.net>
af9dc8
Date: Sat, 6 Jul 2013 07:53:07 -0400
af9dc8
Subject: [PATCH] truncate results at depth of 255 to prevent corruption
af9dc8
af9dc8
---
af9dc8
 ext/xml/xml.c | 90 +++++++++++++++++++++++++++++++++--------------------------
af9dc8
 1 file changed, 50 insertions(+), 40 deletions(-)
af9dc8
af9dc8
diff --git a/ext/xml/xml.c b/ext/xml/xml.c
af9dc8
index 1f0480b..9f0bc30 100644
af9dc8
--- a/ext/xml/xml.c
af9dc8
+++ b/ext/xml/xml.c
af9dc8
@@ -428,7 +428,7 @@ static void xml_parser_dtor(zend_rsrc_list_entry *rsrc TSRMLS_DC)
af9dc8
 	}
af9dc8
 	if (parser->ltags) {
af9dc8
 		int inx;
af9dc8
-		for (inx = 0; inx < parser->level; inx++)
af9dc8
+		for (inx = 0; ((inx < parser->level) && (inx < XML_MAXLEVEL)); inx++)
af9dc8
 			efree(parser->ltags[ inx ]);
af9dc8
 		efree(parser->ltags);
af9dc8
 	}
af9dc8
@@ -805,45 +805,50 @@ void _xml_startElementHandler(void *userData, const XML_Char *name, const XML_Ch
af9dc8
 		} 
af9dc8
 
af9dc8
 		if (parser->data) {
af9dc8
-			zval *tag, *atr;
af9dc8
-			int atcnt = 0;
af9dc8
+			if (parser->level <= XML_MAXLEVEL)  {
af9dc8
+				zval *tag, *atr;
af9dc8
+				int atcnt = 0;
af9dc8
 
af9dc8
-			MAKE_STD_ZVAL(tag);
af9dc8
-			MAKE_STD_ZVAL(atr);
af9dc8
+				MAKE_STD_ZVAL(tag);
af9dc8
+				MAKE_STD_ZVAL(atr);
af9dc8
 
af9dc8
-			array_init(tag);
af9dc8
-			array_init(atr);
af9dc8
+				array_init(tag);
af9dc8
+				array_init(atr);
af9dc8
 
af9dc8
-			_xml_add_to_info(parser,((char *) tag_name) + parser->toffset);
af9dc8
+				_xml_add_to_info(parser,((char *) tag_name) + parser->toffset);
af9dc8
 
af9dc8
-			add_assoc_string(tag,"tag",((char *) tag_name) + parser->toffset,1); /* cast to avoid gcc-warning */
af9dc8
-			add_assoc_string(tag,"type","open",1);
af9dc8
-			add_assoc_long(tag,"level",parser->level);
af9dc8
+				add_assoc_string(tag,"tag",((char *) tag_name) + parser->toffset,1); /* cast to avoid gcc-warning */
af9dc8
+				add_assoc_string(tag,"type","open",1);
af9dc8
+				add_assoc_long(tag,"level",parser->level);
af9dc8
 
af9dc8
-			parser->ltags[parser->level-1] = estrdup(tag_name);
af9dc8
-			parser->lastwasopen = 1;
af9dc8
+				parser->ltags[parser->level-1] = estrdup(tag_name);
af9dc8
+				parser->lastwasopen = 1;
af9dc8
 
af9dc8
-			attributes = (const XML_Char **) attrs;
af9dc8
+				attributes = (const XML_Char **) attrs;
af9dc8
 
af9dc8
-			while (attributes && *attributes) {
af9dc8
-				att = _xml_decode_tag(parser, attributes[0]);
af9dc8
-				val = xml_utf8_decode(attributes[1], strlen(attributes[1]), &val_len, parser->target_encoding);
af9dc8
-				
af9dc8
-				add_assoc_stringl(atr,att,val,val_len,0);
af9dc8
+				while (attributes && *attributes) {
af9dc8
+					att = _xml_decode_tag(parser, attributes[0]);
af9dc8
+					val = xml_utf8_decode(attributes[1], strlen(attributes[1]), &val_len, parser->target_encoding);
af9dc8
 
af9dc8
-				atcnt++;
af9dc8
-				attributes += 2;
af9dc8
+					add_assoc_stringl(atr,att,val,val_len,0);
af9dc8
 
af9dc8
-				efree(att);
af9dc8
-			}
af9dc8
+					atcnt++;
af9dc8
+					attributes += 2;
af9dc8
 
af9dc8
-			if (atcnt) {
af9dc8
-				zend_hash_add(Z_ARRVAL_P(tag),"attributes",sizeof("attributes"),&atr,sizeof(zval*),NULL);
af9dc8
-			} else {
af9dc8
-				zval_ptr_dtor(&atr;;
af9dc8
-			}
af9dc8
+					efree(att);
af9dc8
+				}
af9dc8
+
af9dc8
+				if (atcnt) {
af9dc8
+					zend_hash_add(Z_ARRVAL_P(tag),"attributes",sizeof("attributes"),&atr,sizeof(zval*),NULL);
af9dc8
+				} else {
af9dc8
+					zval_ptr_dtor(&atr;;
af9dc8
+				}
af9dc8
 
af9dc8
-			zend_hash_next_index_insert(Z_ARRVAL_P(parser->data),&tag,sizeof(zval*),(void *) &parser->ctag);
af9dc8
+				zend_hash_next_index_insert(Z_ARRVAL_P(parser->data),&tag,sizeof(zval*),(void *) &parser->ctag);
af9dc8
+			} else if (parser->level == (XML_MAXLEVEL + 1)) {
af9dc8
+				TSRMLS_FETCH();
af9dc8
+				php_error_docref(NULL TSRMLS_CC, E_WARNING, "Maximum depth exceeded - Results truncated");
af9dc8
+			}
af9dc8
 		}
af9dc8
 
af9dc8
 		efree(tag_name);
af9dc8
@@ -895,7 +900,7 @@ void _xml_endElementHandler(void *userData, const XML_Char *name)
af9dc8
 
af9dc8
 		efree(tag_name);
af9dc8
 
af9dc8
-		if (parser->ltags) {
af9dc8
+		if ((parser->ltags) && (parser->level <= XML_MAXLEVEL)) {
af9dc8
 			efree(parser->ltags[parser->level-1]);
af9dc8
 		}
af9dc8
 
af9dc8
@@ -979,18 +984,23 @@ void _xml_characterDataHandler(void *userData, const XML_Char *s, int len)
af9dc8
 						}
af9dc8
 					}
af9dc8
 
af9dc8
-					MAKE_STD_ZVAL(tag);
af9dc8
-					
af9dc8
-					array_init(tag);
af9dc8
-					
af9dc8
-					_xml_add_to_info(parser,parser->ltags[parser->level-1] + parser->toffset);
af9dc8
+					if (parser->level <= XML_MAXLEVEL) {
af9dc8
+						MAKE_STD_ZVAL(tag);
af9dc8
 
af9dc8
-					add_assoc_string(tag,"tag",parser->ltags[parser->level-1] + parser->toffset,1);
af9dc8
-					add_assoc_string(tag,"value",decoded_value,0);
af9dc8
-					add_assoc_string(tag,"type","cdata",1);
af9dc8
-					add_assoc_long(tag,"level",parser->level);
af9dc8
+						array_init(tag);
af9dc8
 
af9dc8
-					zend_hash_next_index_insert(Z_ARRVAL_P(parser->data),&tag,sizeof(zval*),NULL);
af9dc8
+						_xml_add_to_info(parser,parser->ltags[parser->level-1] + parser->toffset);
af9dc8
+
af9dc8
+						add_assoc_string(tag,"tag",parser->ltags[parser->level-1] + parser->toffset,1);
af9dc8
+						add_assoc_string(tag,"value",decoded_value,0);
af9dc8
+						add_assoc_string(tag,"type","cdata",1);
af9dc8
+						add_assoc_long(tag,"level",parser->level);
af9dc8
+
af9dc8
+						zend_hash_next_index_insert(Z_ARRVAL_P(parser->data),&tag,sizeof(zval*),NULL);
af9dc8
+					} else if (parser->level == (XML_MAXLEVEL + 1)) {
af9dc8
+						TSRMLS_FETCH();
af9dc8
+						php_error_docref(NULL TSRMLS_CC, E_WARNING, "Maximum depth exceeded - Results truncated");
af9dc8
+					}
af9dc8
 				}
af9dc8
 			} else {
af9dc8
 				efree(decoded_value);
af9dc8
-- 
af9dc8
1.7.11.5
af9dc8
af9dc8
From 710eee5555bc5c95692bd3c84f5d2b5d687349b6 Mon Sep 17 00:00:00 2001
af9dc8
From: =?utf8?q?Johannes=20Schl=C3=BCter?= <johannes@php.net>
af9dc8
Date: Wed, 10 Jul 2013 19:35:18 +0200
af9dc8
Subject: [PATCH] add test for bug #65236
af9dc8
af9dc8
---
af9dc8
 ext/xml/tests/bug65236.phpt | 15 +++++++++++++++
af9dc8
 1 file changed, 15 insertions(+)
af9dc8
 create mode 100644 ext/xml/tests/bug65236.phpt
af9dc8
af9dc8
diff --git a/ext/xml/tests/bug65236.phpt b/ext/xml/tests/bug65236.phpt
af9dc8
new file mode 100644
af9dc8
index 0000000..67b26d6
af9dc8
--- /dev/null
af9dc8
+++ b/ext/xml/tests/bug65236.phpt
af9dc8
@@ -0,0 +1,15 @@
af9dc8
+--TEST--
af9dc8
+Bug #65236 (heap corruption in xml parser)
af9dc8
+--SKIPIF--
af9dc8
+
af9dc8
+require_once("skipif.inc");
af9dc8
+?>
af9dc8
+--FILE--
af9dc8
+
af9dc8
+xml_parse_into_struct(xml_parser_create_ns(), str_repeat("<blah>", 1000), $a);
af9dc8
+
af9dc8
+echo "Done\n";
af9dc8
+?>
af9dc8
+--EXPECTF--
af9dc8
+Warning: xml_parse_into_struct(): Maximum depth exceeded - Results truncated in %s on line %d
af9dc8
+Done
af9dc8
-- 
af9dc8
1.7.11.5
af9dc8