Bug #68665 [Csd]: Invalid free

From: Date: Mon, 05 Jan 2015 18:12:57 +0000
Subject: Bug #68665 [Csd]: Invalid free
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-189663@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68665&edit=1

 ID:                 68665
 Updated by:         tyrael@php.net
 Reported by:        honey at internot dot info
 Summary:            Invalid free
 Status:             Closed
 Type:               Bug
 Package:            *General Issues
 Operating System:   Linux Ubuntu 14.04
 PHP Version:        master-Git-2014-12-28 (Git)
 Assigned To:        ab
 Block user comment: N
 Private report:     N

 New Comment:

so it seems that this wasn't really a bug.
do we wanna send a headsup to mitre to revoke/reclassify the issue?
I don't think that it is plausible that anybody would ever use an erealloc implementation which
doesn't bail out on failure but return NULL, so I think that the current score for this is
pretty misleading.


Previous Comments:
------------------------------------------------------------------------
[2015-01-01 20:00:26] nikic@php.net

This can't happen at all, because erealloc() is infallible - it will cause a bailout (longjmp)
if it can't perform the allocation.

We probably only keep these checks around to keep the libmagic.patch minimal.

------------------------------------------------------------------------
[2015-01-01 18:57:02] ab@php.net

@honey, yeah, not that easy to trigger that one as it'd only depend on erealloc() fail. So no
tests for that one. And on the other hand, it wloud be only happening when an external magic is used
(and that is dangerous by it self) which is not recommended to do.

Thanks.

------------------------------------------------------------------------
[2015-01-01 10:07:33] honey at internot dot info

Ok, will do(as I've done for 2 just now).

Also @ab, did you make a test-case for the apprentice.c one? A quick look shows it's probably
not possible, since it only happens on a CAST() failure, which I don't think is possible to
trigger.

Thanks,

------------------------------------------------------------------------
[2014-12-31 22:06:55] tyrael@php.net

next time please instead of Bug Type:Bug make sure to use Bug Type: Security and/or drop a mail to
security@php.net
Makes it much easier to track security issues for the Release Managers, makes it easier to have a
proper fix and for high impact issues we usually prefer to wait for the next release before going
public with the bug/fix.

------------------------------------------------------------------------
[2014-12-30 18:50:42] ab@php.net

Ok, see your messages on the OSS security lists :)

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=68665


--
Edit this bug report at https://bugs.php.net/bug.php?id=68665&edit=1


Thread (20 messages)

« previous php.bugs (#189663) next »