From f649adedfe3f0797cd0d6248e1b01c65b326f443 Mon Sep 17 00:00:00 2001 From: "Christoph M. Becker" Date: Sat, 8 Feb 2020 16:56:30 +0100 Subject: Fix #79248: Traversing empty VT_ARRAY throws com_exception If the `VT_ARRAY` is empty, i.e. its upperbound is less than its lower bound, we must not call `php_com_safearray_get_elem()`, because that function throws in this case. --- ext/com_dotnet/com_iterator.c | 2 +- ext/com_dotnet/tests/bug79248.phpt | 16 ++++++++++++++++ 2 files changed, 17 insertions(+), 1 deletion(-) create mode 100644 ext/com_dotnet/tests/bug79248.phpt (limited to 'ext/com_dotnet') diff --git a/ext/com_dotnet/com_iterator.c b/ext/com_dotnet/com_iterator.c index e0d217b395..5b731777e0 100644 --- a/ext/com_dotnet/com_iterator.c +++ b/ext/com_dotnet/com_iterator.c @@ -187,7 +187,7 @@ zend_object_iterator *php_com_iter_get(zend_class_entry *ce, zval *object, int b SafeArrayGetUBound(V_ARRAY(&I->safe_array), 1, &I->sa_max); /* pre-fetch the element */ - if (php_com_safearray_get_elem(&I->safe_array, &I->v, bound)) { + if (I->sa_max >= bound && php_com_safearray_get_elem(&I->safe_array, &I->v, bound)) { I->key = bound; ZVAL_NULL(&ptr); php_com_zval_from_variant(&ptr, &I->v, I->code_page); diff --git a/ext/com_dotnet/tests/bug79248.phpt b/ext/com_dotnet/tests/bug79248.phpt new file mode 100644 index 0000000000..fda67551a7 --- /dev/null +++ b/ext/com_dotnet/tests/bug79248.phpt @@ -0,0 +1,16 @@ +--TEST-- +Bug #79248 (Traversing empty VT_ARRAY throws com_exception) +--SKIPIF-- + +--FILE-- + +--EXPECT-- +done -- cgit v1.2.1