Browse Source

Merge branch 'PHP-5.4' into PHP-5.5

* PHP-5.4:
  fixed possible null deref
pull/391/merge
Anatol Belski 13 years ago
parent
commit
bd20c79423
  1. 8
      TSRM/tsrm_win32.c

8
TSRM/tsrm_win32.c

@ -625,7 +625,7 @@ TSRM_API int shmget(int key, int size, int flags)
shm->info = info_handle; shm->info = info_handle;
shm->descriptor = MapViewOfFileEx(shm->info, FILE_MAP_ALL_ACCESS, 0, 0, 0, NULL); shm->descriptor = MapViewOfFileEx(shm->info, FILE_MAP_ALL_ACCESS, 0, 0, 0, NULL);
if (created) {
if (NULL != shm->descriptor && created) {
shm->descriptor->shm_perm.key = key; shm->descriptor->shm_perm.key = key;
shm->descriptor->shm_segsz = size; shm->descriptor->shm_segsz = size;
shm->descriptor->shm_ctime = time(NULL); shm->descriptor->shm_ctime = time(NULL);
@ -639,8 +639,10 @@ TSRM_API int shmget(int key, int size, int flags)
shm->descriptor->shm_perm.mode = shm->descriptor->shm_perm.seq = 0; shm->descriptor->shm_perm.mode = shm->descriptor->shm_perm.seq = 0;
} }
if (shm->descriptor->shm_perm.key != key || size > shm->descriptor->shm_segsz ) {
CloseHandle(shm->segment);
if (NULL != shm->descriptor && (shm->descriptor->shm_perm.key != key || size > shm->descriptor->shm_segsz)) {
if (NULL != shm->segment) {
CloseHandle(shm->segment);
}
UnmapViewOfFile(shm->descriptor); UnmapViewOfFile(shm->descriptor);
CloseHandle(shm->info); CloseHandle(shm->info);
return -1; return -1;

Loading…
Cancel
Save