Edit report at https://bugs.php.net/bug.php?id=68665&edit=1
ID: 68665
Updated by: ab@php.net
Reported by: honey at internot dot info
Summary: Invalid free
Status: Closed
Type: Bug
Package: *General Issues
Operating System: Linux Ubuntu 14.04
PHP Version: master-Git-2014-12-28 (Git)
Assigned To: ab
Block user comment: N
Private report: N
New Comment:
Ok, see your messages on the OSS security lists :)
Previous Comments:
------------------------------------------------------------------------
[2014-12-30 06:10:48] honey at internot dot info
My bad. It was actually CVE-2014-9426...
------------------------------------------------------------------------
[2014-12-29 19:31:13] honey at internot dot info
OK, so,
apprentice.c has beeen assigned: CVE-2014-9425
this was MITRE's response regarding that zend_language_scanner.l one:
--
There is currently no CVE ID for this. The practice that we follow is
not the same for every piece of software. For example, in the past we
have assigned CVE IDs for vulnerabilities in FFmpeg that did not
affect any FFmpeg release. The rationale for this is that Google was
incorporating unreleased FFmpeg code into Chrome. In the case of PHP,
we do not know of (for example) current cases in which a Linux
distribution ships packages based on using the PHP master tree at an
arbitrary point in time. Also, we have not seen PHP maintainers
advertise that end users should individually use master. Accordingly,
for PHP, master seems to not directly correspond to a "product," and
at least some of the bugs are a reflection of the code being in an
indeterminate development state.
--
Thanks,
------------------------------------------------------------------------
[2014-12-28 21:14:13] honey at internot dot info
Also, I'll contact MITRE in private to see if a non-production, master-git-only falls within
their scope, just in case.
Thanks again,
------------------------------------------------------------------------
[2014-12-28 21:08:11] honey at internot dot info
Ok cool, my name is Joshua Rogers for reference. When I submitted my various bug reports, I
don't think it had an option.
Thanks,
------------------------------------------------------------------------
[2014-12-28 20:47:02] ab@php.net
Hmm, I'd say no. The language scanner one is master only, so shouldn't have been used in
any production.
Offtop - I were glad to push with your names as git doesn't accept pure emails for author
names. Please post that next time )
Thanks.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=68665
--
Edit this bug report at https://bugs.php.net/bug.php?id=68665&edit=1