]> git.pld-linux.org Git - packages/php.git/blobdiff - php-sapi-ini-file.patch
fix for CVE-2015-0232
[packages/php.git] / php-sapi-ini-file.patch
index 5f38403dd513f84964f82ace6d5127b77d20bbdd..0c6abd696e1783c481b4165a4019ecd8ca622d73 100644 (file)
@@ -1,6 +1,19 @@
---- php5.2-200710301730/main/php_ini.c 2007-08-31 11:31:28.000000000 +0300
-+++ php5.2-200710301730-sapi-ini-file/main/php_ini.c   2007-10-30 21:28:48.493329368 +0200
-@@ -463,6 +463,24 @@
+--- php-5.2.11/main/php_ini.c  2009-09-24 22:48:12.128424374 +0300
++++ php-5.2.11/main/php_ini.c  2009-09-24 22:50:19.481745134 +0300
+@@ -255,6 +255,12 @@
+ }
+ /* }}} */
++static int php_csort(const struct dirent **a, const struct dirent **b)
++{
++      return strcmp((*a)->d_name,(*b)->d_name);
++}
++
++
+ /* {{{ php_init_config
+  */
+ int php_init_config(TSRMLS_D)
+@@ -474,6 +480,24 @@
                                }
                        }
                }
 +                              fh.filename = php_ini_opened_path = NULL;
 +                      }
 +              }
-               /* Search php-%sapi-module-name%.ini file in search path */
+               /* Otherwise search for php-%sapi-module-name%.ini file in search path */
                if (!fh.handle.fp) {
-                       const char *fmt = "php-%s.ini";
-@@ -474,13 +492,6 @@
+@@ -486,14 +510,6 @@
                                fh.filename = php_ini_opened_path;
                        }
                }
--              /* Search php.ini file in search path */
+-
+-              /* If still no ini file found, search for php.ini file in search path */
 -              if (!fh.handle.fp) {
 -                      fh.handle.fp = php_fopen_with_path("php.ini", "r", php_ini_search_path, &php_ini_opened_path TSRMLS_CC);
 -                      if (fh.handle.fp) {
@@ -39,9 +53,9 @@
        }
  
        if (free_ini_search_path) {
-@@ -513,9 +524,13 @@
-        * parse any .ini files found in this directory. */
-       if (!sapi_module.php_ini_ignore && strlen(PHP_CONFIG_FILE_SCAN_DIR)) {
+@@ -533,9 +549,13 @@
+       /* Scan and parse any .ini files found in scan path if path not empty. */
+       if (!sapi_module.php_ini_ignore && php_ini_scanned_path_len) {
                struct dirent **namelist;
 -              int ndir, i;
 +              int ndir, i, found = 0;
 +              char *sapi_scan_dir = emalloc(strlen(fmt) + strlen(sapi_module.name));
 +              sprintf(sapi_scan_dir, fmt, sapi_module.name);
  
-               if ((ndir = php_scandir(PHP_CONFIG_FILE_SCAN_DIR, &namelist, 0, php_alphasort)) > 0) {
+-              if ((ndir = php_scandir(php_ini_scanned_path, &namelist, 0, php_alphasort)) > 0) {
++              if ((ndir = php_scandir(php_ini_scanned_path, &namelist, 0, php_csort)) > 0) {
 +                      found += ndir;
                        for (i = 0; i < ndir; i++) {
                                /* check for a .ini extension */
                                if (!(p = strrchr(namelist[i]->d_name, '.')) || (p && strcmp(p, ".ini"))) {
-@@ -532,6 +547,35 @@
+@@ -556,6 +576,35 @@
                                                        /* Here, add it to the list of ini files read */
                                                        l = strlen(ini_file);
                                                        total_l += l + 2;
@@ -68,7 +83,7 @@
 +                      free(namelist);
 +              }
 +
-+              if ((ndir = php_scandir(sapi_scan_dir, &namelist, 0, php_alphasort)) > 0) {
++              if ((ndir = php_scandir(sapi_scan_dir, &namelist, 0, php_csort)) > 0) {
 +                      found += ndir;
 +
 +                      for (i = 0; i < ndir; i++) {
                                                        p = estrndup(ini_file, l);
                                                        zend_llist_add_element(&scanned_ini_list, &p);
                                                }
-@@ -540,8 +584,11 @@
+@@ -564,8 +613,11 @@
                                free(namelist[i]);
                        }
                        free(namelist);
This page took 0.6186 seconds and 4 git commands to generate.