Sec Bug->Bug #68903 [Opn->Nab]: Use after free in Zend/zend_API.c
| From: | stas@php.net | Date: | Sat, 24 Jan 2015 22:45:51 +0000 |
| Subject: | Sec Bug->Bug #68903 [Opn->Nab]: Use after free in Zend/zend_API.c | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-190184@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=68903&edit=1
ID: 68903
Updated by: stas@php.net
Reported by: bugreports at internot dot info
-Summary: Use after free
+Summary: Use after free in Zend/zend_API.c
-Status: Open
+Status: Not a bug
-Type: Security
+Type: Bug
Package: *General Issues
Operating System: Linux Ubuntu 14.04
PHP Version: 5.5.21
Block user comment: N
Private report: Y
New Comment:
The free happens only when interned_name != property_info.name, and this can not happen if
IS_INTERNED(name) branch was taken earlier, since if name is interned,
zend_new_interned_string_int() returns the same string - see code in zend_string.c.
Previous Comments:
------------------------------------------------------------------------
[2015-01-24 19:08:58] bugreports at internot dot info
Description:
------------
Hi,
In /Zend/zend_API.c:
3482 property_info.name = (char*)name;
3493 efree((char*)property_info.name);
but then:
3508 zend_hash_quick_update(&ce->properties_info, name, name_length+1, h,
&property_info, sizeof(zend_property_info), NULL);
which does:
!memcmp(p->arKey, arKey, nKeyLength)
'arKey' = name.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=68903&edit=1