Bug #68665 [Csd]: Invalid free
| From: | honey at internot dot info | Date: | Tue, 06 Jan 2015 00:41:38 +0000 |
| Subject: | Bug #68665 [Csd]: Invalid free | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-189672@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=68665&edit=1
ID: 68665
User updated by: honey at internot dot info
Reported by: honey at internot dot info
Summary: Invalid free
Status: Closed
Type: Bug
Package: *General Issues
Operating System: Linux Ubuntu 14.04
PHP Version: master-Git-2014-12-28 (Git)
Assigned To: ab
Block user comment: N
Private report: N
New Comment:
Sure thing, I'll send it through.
Thanks,
Previous Comments:
------------------------------------------------------------------------
[2015-01-05 18:12:57] tyrael@php.net
so it seems that this wasn't really a bug.
do we wanna send a headsup to mitre to revoke/reclassify the issue?
I don't think that it is plausible that anybody would ever use an erealloc implementation which
doesn't bail out on failure but return NULL, so I think that the current score for this is
pretty misleading.
------------------------------------------------------------------------
[2015-01-01 20:00:26] nikic@php.net
This can't happen at all, because erealloc() is infallible - it will cause a bailout (longjmp)
if it can't perform the allocation.
We probably only keep these checks around to keep the libmagic.patch minimal.
------------------------------------------------------------------------
[2015-01-01 18:57:02] ab@php.net
@honey, yeah, not that easy to trigger that one as it'd only depend on erealloc() fail. So no
tests for that one. And on the other hand, it wloud be only happening when an external magic is used
(and that is dangerous by it self) which is not recommended to do.
Thanks.
------------------------------------------------------------------------
[2015-01-01 10:07:33] honey at internot dot info
Ok, will do(as I've done for 2 just now).
Also @ab, did you make a test-case for the apprentice.c one? A quick look shows it's probably
not possible, since it only happens on a CAST() failure, which I don't think is possible to
trigger.
Thanks,
------------------------------------------------------------------------
[2014-12-31 22:06:55] tyrael@php.net
next time please instead of Bug Type:Bug make sure to use Bug Type: Security and/or drop a mail to
security@php.net
Makes it much easier to track security issues for the Release Managers, makes it easier to have a
proper fix and for high impact issues we usually prefer to wait for the next release before going
public with the bug/fix.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=68665
--
Edit this bug report at https://bugs.php.net/bug.php?id=68665&edit=1