diff options
| author | Antony Dovgal <tony2001@php.net> | 2006-08-06 17:41:51 +0000 |
|---|---|---|
| committer | Antony Dovgal <tony2001@php.net> | 2006-08-06 17:41:51 +0000 |
| commit | 07b5c8fe2a5f3a3714641c543a9d9e12799ac1bb (patch) | |
| tree | af18d79eade0ad8c4095dd6bc859620b4ed918c8 /ext/simplexml | |
| parent | 861c55b41781cc2fd044c1709cba3a9218add754 (diff) | |
| download | php-git-07b5c8fe2a5f3a3714641c543a9d9e12799ac1bb.tar.gz | |
MFH: fix #38347 (Segmentation fault when using foreach with an unknown/empty SimpleXMLElement)
Diffstat (limited to 'ext/simplexml')
| -rw-r--r-- | ext/simplexml/simplexml.c | 3 | ||||
| -rw-r--r-- | ext/simplexml/tests/bug38347.phpt | 28 |
2 files changed, 31 insertions, 0 deletions
diff --git a/ext/simplexml/simplexml.c b/ext/simplexml/simplexml.c index 22757412ca..7a3a335deb 100644 --- a/ext/simplexml/simplexml.c +++ b/ext/simplexml/simplexml.c @@ -195,6 +195,9 @@ static xmlNodePtr sxe_get_element_by_name(php_sxe_object *sxe, xmlNodePtr node, if (sxe->iter.type == SXE_ITER_ELEMENT) { orgnode = sxe_find_element_by_name(sxe, node, sxe->iter.name TSRMLS_CC); + if (!orgnode) { + return NULL; + } node = orgnode->children; } diff --git a/ext/simplexml/tests/bug38347.phpt b/ext/simplexml/tests/bug38347.phpt new file mode 100644 index 0000000000..c25fccea24 --- /dev/null +++ b/ext/simplexml/tests/bug38347.phpt @@ -0,0 +1,28 @@ +--TEST-- +Bug #38347 (Segmentation fault when using foreach with an unknown/empty SimpleXMLElement) +--SKIPIF-- +<?php if (!extension_loaded("simplexml")) print "skip"; ?> +--FILE-- +<?php + +function iterate($xml) +{ + print_r($xml); + foreach ($xml->item as $item) { + echo "This code will crash!"; + } +} + +$xmlstr = "<xml><item>Item 1</item><item>Item 2</item></xml>"; +$xml = simplexml_load_string($xmlstr); +iterate($xml->unknown); + +echo "Done\n"; +?> +--EXPECTF-- +SimpleXMLElement Object +( +) + +Warning: iterate(): Node no longer exists in %s on line %d +Done |
