Edit report at https://bugs.php.net/bug.php?id=68839&edit=1
ID: 68839
User updated by: bugreports at internot dot info
Reported by: bugreports at internot dot info
Summary: Explicit null pointer dereference
Status: Open
Type: Bug
Package: PHAR related
Operating System: Linux Ubuntu 14.04
PHP Version: master-Git-2015-01-15 (Git)
Block user comment: N
Private report: Y
New Comment:
https://github.com/MegaManSec/php-src/commit/7df256e25f778a680f1b7e28c5e6cf4d85ecc0dc
pull request submitted
Previous Comments:
------------------------------------------------------------------------
[2015-01-15 16:19:16] bugreports at internot dot info
Description:
------------
Hi,
The bug itself is in /ext/phar/zip.c, but I'll add the code that I used to find it:
In /ext/phar/phar.c:
2524 return phar_zip_flush(phar, user_stub, len, convert, error);
'error' is NULL at that point, since:
2513 if (error) {
2514 *error = NULL;
2515 }
phar_zip_flush correctly checks for NULL in most places:
1206 if (error) {
1207 spprintf(error, 0, "internal error: attempt to flush cached
zip-based phar \"%s\"", phar->fname);
1208 }
1224 if (error) {
1225 spprintf(error, 0, "unable to set alias in zip-based phar
\"%s\"", phar->fname);
1226 }
1227 return EOF;
etc.
But it does not check for NULL on an unwritable tmp file:
1219 if (entry.fp == NULL) {
1220 spprintf(error, 0, "phar error: unable to create temporary
file");
1221 return EOF;
1222 }
I will be submitting a a patch for this in a moment, to internals@php.
Thanks,
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=68839&edit=1