mirror of
https://github.com/php/php-src.git
synced 2026-04-20 14:31:06 +02:00
This patch adds missing newlines, trims multiple redundant final newlines into a single one, and trims redundant leading newlines in all *.phpt sections. According to POSIX, a line is a sequence of zero or more non-' <newline>' characters plus a terminating '<newline>' character. [1] Files should normally have at least one final newline character. C89 [2] and later standards [3] mention a final newline: "A source file that is not empty shall end in a new-line character, which shall not be immediately preceded by a backslash character." Although it is not mandatory for all files to have a final newline fixed, a more consistent and homogeneous approach brings less of commit differences issues and a better development experience in certain text editors and IDEs. [1] http://pubs.opengroup.org/onlinepubs/9699919799/basedefs/V1_chap03.html#tag_03_206 [2] https://port70.net/~nsz/c/c89/c89-draft.html#2.1.1.2 [3] https://port70.net/~nsz/c/c99/n1256.html#5.1.1.2
70 lines
1.0 KiB
PHP
70 lines
1.0 KiB
PHP
--TEST--
|
|
Bug #70661 (Use After Free Vulnerability in WDDX Packet Deserialization)
|
|
--SKIPIF--
|
|
<?php
|
|
if (!extension_loaded("wddx")) print "skip";
|
|
?>
|
|
--FILE--
|
|
<?php
|
|
$fakezval = ptr2str(1122334455);
|
|
$fakezval .= ptr2str(0);
|
|
$fakezval .= "\x00\x00\x00\x00";
|
|
$fakezval .= "\x01";
|
|
$fakezval .= "\x00";
|
|
$fakezval .= "\x00\x00";
|
|
|
|
$x = <<<EOT
|
|
<?xml version='1.0'?>
|
|
<wddxPacket version='1.0'>
|
|
<header/>
|
|
<data>
|
|
<struct>
|
|
<recordset rowCount='1' fieldNames='ryat'>
|
|
<field name='ryat'>
|
|
<var name='php_class_name'>
|
|
<string>stdClass</string>
|
|
</var>
|
|
<null/>
|
|
</field>
|
|
</recordset>
|
|
</struct>
|
|
</data>
|
|
</wddxPacket>
|
|
EOT;
|
|
|
|
$y = wddx_deserialize($x);
|
|
|
|
for ($i = 0; $i < 5; $i++) {
|
|
$v[$i] = $fakezval.$i;
|
|
}
|
|
|
|
var_dump($y);
|
|
|
|
function ptr2str($ptr)
|
|
{
|
|
$out = '';
|
|
|
|
for ($i = 0; $i < 8; $i++) {
|
|
$out .= chr($ptr & 0xff);
|
|
$ptr >>= 8;
|
|
}
|
|
|
|
return $out;
|
|
}
|
|
?>
|
|
DONE
|
|
--EXPECT--
|
|
array(1) {
|
|
[0]=>
|
|
array(1) {
|
|
["ryat"]=>
|
|
array(2) {
|
|
["php_class_name"]=>
|
|
string(8) "stdClass"
|
|
[0]=>
|
|
NULL
|
|
}
|
|
}
|
|
}
|
|
DONE
|