Edit report at https://bugs.php.net/bug.php?id=68665&edit=1
ID: 68665
Comment by: honey at internot dot info
Reported by: honey at internot dot info
Summary: Invalid free
Status: Closed
Type: Bug
Package: *General Issues
Operating System: Linux Ubuntu 14.04
PHP Version: master-Git-2014-12-28 (Git)
Assigned To: ab
Block user comment: N
Private report: N
New Comment:
Ok, will do(as I've done for 2 just now).
Also @ab, did you make a test-case for the apprentice.c one? A quick look shows it's probably
not possible, since it only happens on a CAST() failure, which I don't think is possible to
trigger.
Thanks,
Previous Comments:
------------------------------------------------------------------------
[2014-12-31 22:06:55] tyrael@php.net
next time please instead of Bug Type:Bug make sure to use Bug Type: Security and/or drop a mail to
security@php.net
Makes it much easier to track security issues for the Release Managers, makes it easier to have a
proper fix and for high impact issues we usually prefer to wait for the next release before going
public with the bug/fix.
------------------------------------------------------------------------
[2014-12-30 18:50:42] ab@php.net
Ok, see your messages on the OSS security lists :)
------------------------------------------------------------------------
[2014-12-30 06:10:48] honey at internot dot info
My bad. It was actually CVE-2014-9426...
------------------------------------------------------------------------
[2014-12-29 19:31:13] honey at internot dot info
OK, so,
apprentice.c has beeen assigned: CVE-2014-9425
this was MITRE's response regarding that zend_language_scanner.l one:
--
There is currently no CVE ID for this. The practice that we follow is
not the same for every piece of software. For example, in the past we
have assigned CVE IDs for vulnerabilities in FFmpeg that did not
affect any FFmpeg release. The rationale for this is that Google was
incorporating unreleased FFmpeg code into Chrome. In the case of PHP,
we do not know of (for example) current cases in which a Linux
distribution ships packages based on using the PHP master tree at an
arbitrary point in time. Also, we have not seen PHP maintainers
advertise that end users should individually use master. Accordingly,
for PHP, master seems to not directly correspond to a "product," and
at least some of the bugs are a reflection of the code being in an
indeterminate development state.
--
Thanks,
------------------------------------------------------------------------
[2014-12-28 21:14:13] honey at internot dot info
Also, I'll contact MITRE in private to see if a non-production, master-git-only falls within
their scope, just in case.
Thanks again,
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=68665
--
Edit this bug report at https://bugs.php.net/bug.php?id=68665&edit=1