Bug #68817 [Opn->Csd]: Null pointer deference

From: Date: Thu, 15 Jan 2015 00:13:04 +0000
Subject: Bug #68817 [Opn->Csd]: Null pointer deference
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-189961@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68817&edit=1 ID: 68817 Updated by: stas@php.net Reported by: bugreports at internot dot info Summary: Null pointer deference -Status: Open +Status: Closed Type: Bug Package: JSON related Operating System: Linux Ubuntu 14.04 PHP Version: master-Git-2015-01-12 (Git) Block user comment: N Private report: N New Comment: Automatic comment on behalf of stas Revision: http://git.php.net/?p=php-src.git;a=commit;h=7f95aa4d97b6a687f7b4565157b934610d354f43 Log: Fix bug #68817: Null pointer deference Previous Comments: ------------------------------------------------------------------------ [2015-01-15 00:07:20] stas@php.net Actually, this report appears to be correct - decoding [""] via json_decode produces a segfault for me. Initializing buf doesn't help since it's initialized to 0, so buf.s->len still can have null deref. This code is in master only (older code uses buf.len which has no pointer) so no reason to keep it private. ------------------------------------------------------------------------ [2015-01-14 12:40:15] bugreports at internot dot info Yes. And the if() at line 564 could/should probably be removed, then. Thanks, ------------------------------------------------------------------------ [2015-01-14 09:36:03] tony2001@php.net Because Nikita Popov added it in b30c7fe2 for some reason. Do I understand it correctly that you don't have a reproduce case and just trying to deduce security problem by looking at the code? ------------------------------------------------------------------------ [2015-01-13 17:09:14] bugreports at internot dot info Why is there a check on line 564 then? Thanks, ------------------------------------------------------------------------ [2015-01-13 09:45:35] tony2001@php.net But it is initialized at the top of the func: smart_str buf = {0}; Do you have a reproduce case? ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=68817 -- Edit this bug report at https://bugs.php.net/bug.php?id=68817&edit=1

« previous php.bugs (#189961) next »