diff options
author | Jakub Zelenka <bukka@php.net> | 2015-06-21 15:30:33 +0100 |
---|---|---|
committer | Jakub Zelenka <bukka@php.net> | 2015-06-21 15:30:33 +0100 |
commit | f3df3df8737ace9f4431416fdd0d312cb0ee9cfd (patch) | |
tree | 4d1031a3f6156ea1a83c94e39018118077f87d59 /ext/json/json_parser.tab.c | |
parent | 115e9288bbd28f7ad525ebcc0053908464be5c95 (diff) | |
download | php-git-f3df3df8737ace9f4431416fdd0d312cb0ee9cfd.tar.gz |
Fix bug #68546 (json_decode cannot access property started with \0)
Diffstat (limited to 'ext/json/json_parser.tab.c')
-rw-r--r-- | ext/json/json_parser.tab.c | 24 |
1 files changed, 17 insertions, 7 deletions
diff --git a/ext/json/json_parser.tab.c b/ext/json/json_parser.tab.c index 45a982bbcc..052fc17137 100644 --- a/ext/json/json_parser.tab.c +++ b/ext/json/json_parser.tab.c @@ -204,7 +204,7 @@ int php_json_yyparse (php_json_parser *parser); int php_json_yylex(union YYSTYPE *value, php_json_parser *parser); void php_json_yyerror(php_json_parser *parser, char const *msg); void php_json_parser_object_init(php_json_parser *parser, zval *object); -void php_json_parser_object_update(php_json_parser *parser, zval *object, zend_string *key, zval *zvalue); +int php_json_parser_object_update(php_json_parser *parser, zval *object, zend_string *key, zval *zvalue); void php_json_parser_array_init(zval *object); void php_json_parser_array_append(zval *array, zval *zvalue); @@ -515,9 +515,9 @@ static const yytype_uint8 yytranslate[] = static const yytype_uint8 yyrline[] = { 0, 92, 92, 98, 105, 105, 113, 114, 123, 126, - 130, 135, 140, 147, 152, 159, 159, 167, 168, 177, - 180, 184, 189, 194, 201, 202, 206, 207, 208, 209, - 210, 211, 212, 213, 214, 215, 219 + 130, 136, 142, 149, 154, 161, 161, 169, 170, 179, + 182, 186, 191, 196, 203, 204, 208, 209, 210, 211, + 212, 213, 214, 215, 216, 217, 221 }; #endif @@ -1499,7 +1499,8 @@ yyreduce: { php_json_parser_object_init(parser, &(yyval.value)); - php_json_parser_object_update(parser, &(yyval.value), (yyvsp[0].pair).key, &(yyvsp[0].pair).val); + if (php_json_parser_object_update(parser, &(yyval.value), (yyvsp[0].pair).key, &(yyvsp[0].pair).val) == FAILURE) + YYERROR; } break; @@ -1507,7 +1508,8 @@ yyreduce: case 11: { - php_json_parser_object_update(parser, &(yyvsp[-2].value), (yyvsp[0].pair).key, &(yyvsp[0].pair).val); + if (php_json_parser_object_update(parser, &(yyvsp[-2].value), (yyvsp[0].pair).key, &(yyvsp[0].pair).val) == FAILURE) + YYERROR; ZVAL_COPY_VALUE(&(yyval.value), &(yyvsp[-2].value)); } @@ -1860,7 +1862,7 @@ void php_json_parser_object_init(php_json_parser *parser, zval *object) } } -void php_json_parser_object_update(php_json_parser *parser, zval *object, zend_string *key, zval *zvalue) +int php_json_parser_object_update(php_json_parser *parser, zval *object, zend_string *key, zval *zvalue) { /* if JSON_OBJECT_AS_ARRAY is set */ if (Z_TYPE_P(object) == IS_ARRAY) { @@ -1870,6 +1872,12 @@ void php_json_parser_object_update(php_json_parser *parser, zval *object, zend_s if (key->len == 0) { zend_string_release(key); key = zend_string_init("_empty_", sizeof("_empty_") - 1, 0); + } else if (key->val[0] == '\0') { + parser->scanner.errcode = PHP_JSON_ERROR_INVALID_PROPERTY_NAME; + zend_string_release(key); + zval_dtor(zvalue); + zval_dtor(object); + return FAILURE; } ZVAL_NEW_STR(&zkey, key); zend_std_write_property(object, &zkey, zvalue, NULL); @@ -1879,6 +1887,8 @@ void php_json_parser_object_update(php_json_parser *parser, zval *object, zend_s } } zend_string_release(key); + + return SUCCESS; } void php_json_parser_array_init(zval *array) |