Bug #68839 [Opn]: Explicit null pointer dereference

From: Date: Fri, 16 Jan 2015 08:21:03 +0000
Subject: Bug #68839 [Opn]: Explicit null pointer dereference
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-189984@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68839&edit=1

 ID:                 68839
 User updated by:    bugreports at internot dot info
 Reported by:        bugreports at internot dot info
 Summary:            Explicit null pointer dereference
 Status:             Open
 Type:               Bug
 Package:            PHAR related
 Operating System:   Linux Ubuntu 14.04
 PHP Version:        master-Git-2015-01-15 (Git)
 Block user comment: N
 Private report:     Y

 New Comment:

https://github.com/MegaManSec/php-src/commit/7df256e25f778a680f1b7e28c5e6cf4d85ecc0dc
pull request submitted


Previous Comments:
------------------------------------------------------------------------
[2015-01-15 16:19:16] bugreports at internot dot info

Description:
------------
Hi,

The bug itself is in /ext/phar/zip.c, but I'll add the code that I used to find it:


In /ext/phar/phar.c:


2524                return phar_zip_flush(phar, user_stub, len, convert, error);


'error' is NULL at that point, since:
2513        if (error) {
2514                *error = NULL;
2515        }


phar_zip_flush correctly checks for NULL in most places:

1206                if (error) {
1207                        spprintf(error, 0, "internal error: attempt to flush cached
zip-based phar \"%s\"", phar->fname);
1208                }

1224                        if (error) {
1225                                spprintf(error, 0, "unable to set alias in zip-based phar
\"%s\"", phar->fname);
1226                        }
1227                        return EOF;

etc.

But it does not check for NULL on an unwritable tmp file:

1219                if (entry.fp == NULL) {
1220                        spprintf(error, 0, "phar error: unable to create temporary
file");
1221                        return EOF;
1222                }




I will be  submitting a a patch for this in a moment, to internals@php.


Thanks,



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=68839&edit=1


Thread (1 message)

  • bugreports at internot dot info
  • Unknown Message
    • bugreports at internot dot info
« previous php.bugs (#189984) next »