Req #68827 [Opn]: Double free
| From: | ab@php.net | Date: | Thu, 22 Jan 2015 07:44:09 +0000 |
| Subject: | Req #68827 [Opn]: Double free | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-190130@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=68827&edit=1
ID: 68827
Updated by: ab@php.net
Reported by: bugreports at internot dot info
Summary: Double free
Status: Open
Type: Feature/Change Request
Package: *General Issues
Operating System: Linux Ubuntu 14.04
PHP Version: master-Git-2015-01-13 (Git)
-Assigned To:
+Assigned To: ab
Block user comment: N
Private report: N
New Comment:
Looks like it's an issue in the PHP patch, the latest libmagic looks fine https://github.com/file/file/blob/master/src/apprentice.c#L1283
. Despite it's only an issue with disabled ZMM, worth fixing.
Thanks.
Previous Comments:
------------------------------------------------------------------------
[2015-01-22 00:31:38] pajoye@php.net
@stas
as it is a fileinfo issue and should also reported there, we do bundle it, patched. So it affects
PHP more directly too. We should apply the fix.
------------------------------------------------------------------------
[2015-01-14 23:19:54] stas@php.net
This is a file from fileinfo library, so it may make sense to report the issue here; http://bugs.gw.com/my_view_page.php
In this particular case return NULL may indeed be faster, but I don't see any security issue or
PHP-related bug here.
------------------------------------------------------------------------
[2015-01-14 12:44:47] bugreports at internot dot info
Ahh, I see!
Well, then, this code:
2611 efree(map);
2612 goto error;
should just be replaced with
return NULL;
since 'dbname', and 'stream' are not used at that stage.
Thanks,
------------------------------------------------------------------------
[2015-01-14 12:33:10] tony2001@php.net
That's correct, efree() doesn't modify the pointer.
But it's already NULL at the time efree() is called, take a look at the if condition:
if ((map = CAST(struct magic_map *, ecalloc(1, sizeof(*map)))) == NULL) {
file_oomem(ms, sizeof(*map));
efree(map);
goto error;
}
------------------------------------------------------------------------
[2015-01-14 12:17:16] bugreports at internot dot info
'map' is not NULL. efree(map) doesn't set map=NULL;.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=68827
--
Edit this bug report at https://bugs.php.net/bug.php?id=68827&edit=1