Bug #68740 [Opn->Csd]: null pointer deference

From: Date: Thu, 08 Jan 2015 08:15:32 +0000
Subject: Bug #68740 [Opn->Csd]: null pointer deference
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-189731@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68740&edit=1 ID: 68740 Updated by: laruence@php.net Reported by: bugreports at internot dot info Summary: null pointer deference -Status: Open +Status: Closed Type: Bug Package: Regexps related Operating System: Linux Ubuntu 14.04 PHP Version: master-Git-2015-01-04 (Git) -Assigned To: +Assigned To: laruence Block user comment: N Private report: N New Comment: The fix for this bug has been committed. Snapshots of the sources are packaged every three hours; this change will be in the next snapshot. You can grab the snapshot at http://snaps.php.net/. For Windows: http://windows.php.net/snapshots/ Thank you for the report, and for helping us make PHP better. Previous Comments: ------------------------------------------------------------------------ [2015-01-08 08:09:53] laruence@php.net Automatic comment on behalf of laruence Revision: http://git.php.net/?p=php-src.git;a=commit;h=124fb22a13fafa3648e4e15b4f207c7096d8155e Log: Fixed bug #68739 #68740 #68741 ------------------------------------------------------------------------ [2015-01-04 10:21:45] bugreports at internot dot info Description: ------------ Hi, An explicit null deference happens in /ext/ereg/regex/regcomp.c: 140 g->setbits = NULL; then this is called: 167 categorize(p, g); which does this: 1326 if (cats[c] == 0 && isinsets(g, c)) { And then the isinsets function does this: 1279 for (i = 0, col = g->setbits; i < ncols; i++, col += g->csetsize) 1280 if (col[uc] != 0) 1281 return(1); which will cause a crash. Thanks, ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=68740&edit=1

« previous php.bugs (#189731) next »