Bug #68665 [Csd]: Invalid free

From: Date: Tue, 30 Dec 2014 06:10:49 +0000
Subject: Bug #68665 [Csd]: Invalid free
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-189333@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68665&edit=1 ID: 68665 User updated by: honey at internot dot info Reported by: honey at internot dot info Summary: Invalid free Status: Closed Type: Bug Package: *General Issues Operating System: Linux Ubuntu 14.04 PHP Version: master-Git-2014-12-28 (Git) Assigned To: ab Block user comment: N Private report: N New Comment: My bad. It was actually CVE-2014-9426... Previous Comments: ------------------------------------------------------------------------ [2014-12-29 19:31:13] honey at internot dot info OK, so, apprentice.c has beeen assigned: CVE-2014-9425 this was MITRE's response regarding that zend_language_scanner.l one: -- There is currently no CVE ID for this. The practice that we follow is not the same for every piece of software. For example, in the past we have assigned CVE IDs for vulnerabilities in FFmpeg that did not affect any FFmpeg release. The rationale for this is that Google was incorporating unreleased FFmpeg code into Chrome. In the case of PHP, we do not know of (for example) current cases in which a Linux distribution ships packages based on using the PHP master tree at an arbitrary point in time. Also, we have not seen PHP maintainers advertise that end users should individually use master. Accordingly, for PHP, master seems to not directly correspond to a "product," and at least some of the bugs are a reflection of the code being in an indeterminate development state. -- Thanks, ------------------------------------------------------------------------ [2014-12-28 21:14:13] honey at internot dot info Also, I'll contact MITRE in private to see if a non-production, master-git-only falls within their scope, just in case. Thanks again, ------------------------------------------------------------------------ [2014-12-28 21:08:11] honey at internot dot info Ok cool, my name is Joshua Rogers for reference. When I submitted my various bug reports, I don't think it had an option. Thanks, ------------------------------------------------------------------------ [2014-12-28 20:47:02] ab@php.net Hmm, I'd say no. The language scanner one is master only, so shouldn't have been used in any production. Offtop - I were glad to push with your names as git doesn't accept pure emails for author names. Please post that next time ) Thanks. ------------------------------------------------------------------------ [2014-12-28 20:18:28] honey at internot dot info Ok, cool. Should I submit a CVE-ID request to MITRE/oss-security? Thanks, ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=68665 -- Edit this bug report at https://bugs.php.net/bug.php?id=68665&edit=1

« previous php.bugs (#189333) next »