Bug #60042 [Csd]: spl_autoload_call may manipulate a dangling pointer
| From: | tom at punkave dot com | Date: | Wed, 12 Oct 2011 12:55:18 +0000 |
| Subject: | Bug #60042 [Csd]: spl_autoload_call may manipulate a dangling pointer | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-164257@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=60042&edit=1
ID: 60042
User updated by: tom at punkave dot com
Reported by: tom at punkave dot com
Summary: spl_autoload_call may manipulate a dangling pointer
Status: Closed
Type: Bug
Package: SPL related
Operating System: Any
PHP Version: 5.3.8
Assigned To: felipe
Block user comment: N
Private report: N
New Comment:
Thanks for hitting it so quickly!
Previous Comments:
------------------------------------------------------------------------
[2011-10-12 01:02:59] felipe@php.net
This bug has been fixed in SVN.
Snapshots of the sources are packaged every three hours; this change
will be in the next snapshot. You can grab the snapshot at
http://snaps.php.net/.
For Windows:
http://windows.php.net/snapshots/
Thank you for the report, and for helping us make PHP better.
;)
------------------------------------------------------------------------
[2011-10-12 01:02:51] felipe@php.net
Automatic comment from SVN on behalf of felipe
Revision: http://svn.php.net/viewvc/?view=revision&revision=318040
Log: - Fixed bug #60042 (spl_autoload_call may manipulate a dangling pointer)
patch by: tom at punkave dot com
------------------------------------------------------------------------
[2011-10-12 00:59:42] felipe@php.net
Ah, right. I didn't see the loop.
------------------------------------------------------------------------
[2011-10-12 00:28:10] tom at punkave dot com
But there's a while loop, and if there are multiple iterations through the loop
and one of them doesn't change retval then the same value is destroyed more than
once, isn't it? That's bad, right?
------------------------------------------------------------------------
[2011-10-11 22:12:32] felipe@php.net
The retval variable doesn't need to be set to NULL there. The pointer only live in the current
scope and it isn't used after zval_ptr_dtor.
Thanks.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=60042
--
Edit this bug report at https://bugs.php.net/bug.php?id=60042&edit=1