Skip site navigation (1) Skip section navigation (2)

Bug in ResolveOneParam()

From: Rainer Bauer <usenet(at)munnin(dot)com>
To: pgsql-odbc(at)postgresql(dot)org
Subject: Bug in ResolveOneParam()
Date: 2007-07-16 10:09:59
Message-ID: (view raw, whole thread or download thread mbox)
Lists: pgsql-odbc

I finally was able to track down the bug that occasionally happened when
UseServerSidePrepare was enabled: the driver is writing past allocated memory.

The bug is in ResolveOneParam(). At one point this function writes directly
into the allocated buffer <qb->query_statement> _without_ checking the
allocated size by calling enlarge_query_statement().

I have added the ENLARGE_NEWSTATEMENT() call which should take care of this
bug (see attached patch).


Index: convert.c
RCS file: /cvsroot/psqlodbc/psqlodbc/convert.c,v
retrieving revision 1.161
diff -u -r1.161 convert.c
--- convert.c	4 Jun 2007 10:24:49 -0000	1.161
+++ convert.c	16 Jul 2007 09:52:51 -0000
@@ -3459,6 +3472,7 @@
 	} */
 	if (req_bind)
+		ENLARGE_NEWSTATEMENT( qb, (qb->npos+4) );
 		npos = qb->npos;
 		qb->npos += 4;


pgsql-odbc by date

Next:From: Rainer BauerDate: 2007-07-16 10:11:01
Subject: Return value of enlarge_query_statement() is never evaluated
Previous:From: Ludek FinstrleDate: 2007-07-16 09:50:28
Subject: Re: Error in 'psqlodbca.dll'

Privacy Policy | About PostgreSQL
Copyright © 1996-2017 The PostgreSQL Global Development Group