diff options
author | Anatol Belski <ab@php.net> | 2016-11-03 17:03:23 +0100 |
---|---|---|
committer | Anatol Belski <ab@php.net> | 2016-11-08 13:02:49 +0100 |
commit | 35df4b1ae3cc9a3df4e99565037cee204280332e (patch) | |
tree | e201f1071a1460474fd3b534b2651ceba140a759 | |
parent | a05e84c42bfbff1f2ab17dfcb3311b55ff63f0a1 (diff) | |
download | php-git-35df4b1ae3cc9a3df4e99565037cee204280332e.tar.gz |
Fixed bug #73418 Integer Overflow in "_php_imap_mail" leads to crash
(cherry picked from commit 99b242a6d093bca1f64084866b4491061de57553)
(cherry picked from commit de643586dee986ff16c0a6be44813687786aa781)
-rw-r--r-- | ext/imap/php_imap.c | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/ext/imap/php_imap.c b/ext/imap/php_imap.c index 566392fbfd..48229b5227 100644 --- a/ext/imap/php_imap.c +++ b/ext/imap/php_imap.c @@ -3934,7 +3934,7 @@ int _php_imap_mail(char *to, char *subject, char *message, char *headers, char * char *tsm_errmsg = NULL; ADDRESS *addr; char *bufferTo = NULL, *bufferCc = NULL, *bufferBcc = NULL, *bufferHeader = NULL; - int offset, bufferLen = 0; + size_t offset, bufferLen = 0; size_t bt_len; if (headers) { |