]> granicus.if.org Git - php/commitdiff
Fixed bug #73418 Integer Overflow in "_php_imap_mail" leads to crash
authorAnatol Belski <ab@php.net>
Thu, 3 Nov 2016 16:03:23 +0000 (17:03 +0100)
committerAnatol Belski <ab@php.net>
Thu, 3 Nov 2016 16:03:23 +0000 (17:03 +0100)
ext/imap/php_imap.c

index 564473b73823437b18016d3126cdb09203f1b879..6c392fb0fb89c60a338d90eed39602ffa8fbd4e5 100644 (file)
@@ -3900,7 +3900,7 @@ int _php_imap_mail(char *to, char *subject, char *message, char *headers, char *
        char *tsm_errmsg = NULL;
        ADDRESS *addr;
        char *bufferTo = NULL, *bufferCc = NULL, *bufferBcc = NULL, *bufferHeader = NULL;
-       int offset, bufferLen = 0;
+       size_t offset, bufferLen = 0;
        size_t bt_len;
 
        if (headers) {