Bug #68740 [Opn->Csd]: null pointer deference
| From: | laruence@php.net | Date: | Thu, 08 Jan 2015 08:15:32 +0000 |
| Subject: | Bug #68740 [Opn->Csd]: null pointer deference | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-189731@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=68740&edit=1
ID: 68740
Updated by: laruence@php.net
Reported by: bugreports at internot dot info
Summary: null pointer deference
-Status: Open
+Status: Closed
Type: Bug
Package: Regexps related
Operating System: Linux Ubuntu 14.04
PHP Version: master-Git-2015-01-04 (Git)
-Assigned To:
+Assigned To: laruence
Block user comment: N
Private report: N
New Comment:
The fix for this bug has been committed.
Snapshots of the sources are packaged every three hours; this change
will be in the next snapshot. You can grab the snapshot at
http://snaps.php.net/.
For Windows:
http://windows.php.net/snapshots/
Thank you for the report, and for helping us make PHP better.
Previous Comments:
------------------------------------------------------------------------
[2015-01-08 08:09:53] laruence@php.net
Automatic comment on behalf of laruence
Revision: http://git.php.net/?p=php-src.git;a=commit;h=124fb22a13fafa3648e4e15b4f207c7096d8155e
Log: Fixed bug #68739 #68740 #68741
------------------------------------------------------------------------
[2015-01-04 10:21:45] bugreports at internot dot info
Description:
------------
Hi,
An explicit null deference happens in /ext/ereg/regex/regcomp.c:
140 g->setbits = NULL;
then this is called:
167 categorize(p, g);
which does this:
1326 if (cats[c] == 0 && isinsets(g, c)) {
And then the isinsets function does this:
1279 for (i = 0, col = g->setbits; i < ncols; i++, col += g->csetsize)
1280 if (col[uc] != 0)
1281 return(1);
which will cause a crash.
Thanks,
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=68740&edit=1