Bug #68817 [Opn->Csd]: Null pointer deference
| From: | stas@php.net | Date: | Thu, 15 Jan 2015 00:13:04 +0000 |
| Subject: | Bug #68817 [Opn->Csd]: Null pointer deference | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-189961@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=68817&edit=1
ID: 68817
Updated by: stas@php.net
Reported by: bugreports at internot dot info
Summary: Null pointer deference
-Status: Open
+Status: Closed
Type: Bug
Package: JSON related
Operating System: Linux Ubuntu 14.04
PHP Version: master-Git-2015-01-12 (Git)
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of stas
Revision: http://git.php.net/?p=php-src.git;a=commit;h=7f95aa4d97b6a687f7b4565157b934610d354f43
Log: Fix bug #68817: Null pointer deference
Previous Comments:
------------------------------------------------------------------------
[2015-01-15 00:07:20] stas@php.net
Actually, this report appears to be correct - decoding [""] via json_decode produces a
segfault for me. Initializing buf doesn't help since it's initialized to 0, so
buf.s->len still can have null deref. This code is in master only (older code uses buf.len which
has no pointer) so no reason to keep it private.
------------------------------------------------------------------------
[2015-01-14 12:40:15] bugreports at internot dot info
Yes.
And the if() at line 564 could/should probably be removed, then.
Thanks,
------------------------------------------------------------------------
[2015-01-14 09:36:03] tony2001@php.net
Because Nikita Popov added it in b30c7fe2 for some reason.
Do I understand it correctly that you don't have a reproduce case and just trying to deduce
security problem by looking at the code?
------------------------------------------------------------------------
[2015-01-13 17:09:14] bugreports at internot dot info
Why is there a check on line 564 then?
Thanks,
------------------------------------------------------------------------
[2015-01-13 09:45:35] tony2001@php.net
But it is initialized at the top of the func:
smart_str buf = {0};
Do you have a reproduce case?
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=68817
--
Edit this bug report at https://bugs.php.net/bug.php?id=68817&edit=1