Bug #68665 [Csd]: Invalid free

From: Date: Tue, 30 Dec 2014 18:50:42 +0000
Subject: Bug #68665 [Csd]: Invalid free
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-189545@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68665&edit=1

 ID:                 68665
 Updated by:         ab@php.net
 Reported by:        honey at internot dot info
 Summary:            Invalid free
 Status:             Closed
 Type:               Bug
 Package:            *General Issues
 Operating System:   Linux Ubuntu 14.04
 PHP Version:        master-Git-2014-12-28 (Git)
 Assigned To:        ab
 Block user comment: N
 Private report:     N

 New Comment:

Ok, see your messages on the OSS security lists :)


Previous Comments:
------------------------------------------------------------------------
[2014-12-30 06:10:48] honey at internot dot info

My bad. It was actually CVE-2014-9426...

------------------------------------------------------------------------
[2014-12-29 19:31:13] honey at internot dot info

OK, so, 

apprentice.c has beeen assigned: CVE-2014-9425


this was MITRE's response regarding that zend_language_scanner.l one:

--


There is currently no CVE ID for this. The practice that we follow is
not the same for every piece of software. For example, in the past we
have assigned CVE IDs for vulnerabilities in FFmpeg that did not
affect any FFmpeg release. The rationale for this is that Google was
incorporating unreleased FFmpeg code into Chrome. In the case of PHP,
we do not know of (for example) current cases in which a Linux
distribution ships packages based on using the PHP master tree at an
arbitrary point in time. Also, we have not seen PHP maintainers
advertise that end users should individually use master. Accordingly,
for PHP, master seems to not directly correspond to a "product," and
at least some of the bugs are a reflection of the code being in an
indeterminate development state.

--



Thanks,

------------------------------------------------------------------------
[2014-12-28 21:14:13] honey at internot dot info

Also, I'll contact MITRE in private to see if a non-production, master-git-only falls within
their scope, just in case.

Thanks again,

------------------------------------------------------------------------
[2014-12-28 21:08:11] honey at internot dot info

Ok cool, my name is Joshua Rogers for reference. When I submitted my various bug reports, I
don't think it had an option.

Thanks,

------------------------------------------------------------------------
[2014-12-28 20:47:02] ab@php.net

Hmm, I'd say no. The language scanner one is master only, so shouldn't have been used in
any production.

Offtop - I were glad to push with your names as git doesn't accept pure emails for author
names. Please post that next time )

Thanks.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=68665


--
Edit this bug report at https://bugs.php.net/bug.php?id=68665&edit=1


Thread (20 messages)

« previous php.bugs (#189545) next »