Sec Bug->Bug #68839 [Opn]: Explicit null pointer dereference

From: Date: Thu, 15 Jan 2015 17:10:27 +0000
Subject: Sec Bug->Bug #68839 [Opn]: Explicit null pointer dereference
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-189974@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68839&edit=1 ID: 68839 Updated by: tony2001@php.net Reported by: bugreports at internot dot info Summary: Explicit null pointer dereference Status: Open -Type: Security +Type: Bug Package: PHAR related Operating System: Linux Ubuntu 14.04 PHP Version: master-Git-2015-01-15 (Git) Block user comment: N Private report: Y Previous Comments: ------------------------------------------------------------------------ [2015-01-15 16:19:16] bugreports at internot dot info Description: ------------ Hi, The bug itself is in /ext/phar/zip.c, but I'll add the code that I used to find it: In /ext/phar/phar.c: 2524 return phar_zip_flush(phar, user_stub, len, convert, error); 'error' is NULL at that point, since: 2513 if (error) { 2514 *error = NULL; 2515 } phar_zip_flush correctly checks for NULL in most places: 1206 if (error) { 1207 spprintf(error, 0, "internal error: attempt to flush cached zip-based phar \"%s\"", phar->fname); 1208 } 1224 if (error) { 1225 spprintf(error, 0, "unable to set alias in zip-based phar \"%s\"", phar->fname); 1226 } 1227 return EOF; etc. But it does not check for NULL on an unwritable tmp file: 1219 if (entry.fp == NULL) { 1220 spprintf(error, 0, "phar error: unable to create temporary file"); 1221 return EOF; 1222 } I will be submitting a a patch for this in a moment, to internals@php. Thanks, ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=68839&edit=1

« previous php.bugs (#189974) next »