tony2001 Fri Feb 15 09:33:00 2008 UTC Modified files: /php-src/ext/standard array.c Log: recursion protection in count() http://cvs.php.net/viewvc.cgi/php-src/ext/standard/array.c?r1=1.445&r2=1.446&diff_format=u Index: php-src/ext/standard/array.c diff -u php-src/ext/standard/array.c:1.445 php-src/ext/standard/array.c:1.446 --- php-src/ext/standard/array.c:1.445 Thu Feb 14 14:17:32 2008 +++ php-src/ext/standard/array.c Fri Feb 15 09:33:00 2008 @@ -21,7 +21,7 @@ +----------------------------------------------------------------------+ */ -/* $Id: array.c,v 1.445 2008/02/14 14:17:32 felipe Exp $ */ +/* $Id: array.c,v 1.446 2008/02/15 09:33:00 tony2001 Exp $ */ #include "php.h" #include "php_ini.h" @@ -281,6 +281,11 @@ zval **element; if (Z_TYPE_P(array) == IS_ARRAY) { + if (Z_ARRVAL_P(array)->nApplyCount > 1) { + php_error_docref(NULL TSRMLS_CC, E_WARNING, "recursion detected"); + return 0; + } + cnt = zend_hash_num_elements(Z_ARRVAL_P(array)); if (mode == COUNT_RECURSIVE) { HashPosition pos; @@ -289,7 +294,9 @@ zend_hash_get_current_data_ex(Z_ARRVAL_P(array), (void **) &element, &pos) == SUCCESS; zend_hash_move_forward_ex(Z_ARRVAL_P(array), &pos) ) { + Z_ARRVAL_P(array)->nApplyCount++; cnt += php_count_recursive(*element, COUNT_RECURSIVE TSRMLS_CC); + Z_ARRVAL_P(array)->nApplyCount--; } } }
-- PHP CVS Mailing List (http://www.php.net/) To unsubscribe, visit: http://www.php.net/unsub.php