Sec Bug->Bug #68900 [Opn->Nab]: Pointer use after free

From: Date: Sat, 24 Jan 2015 23:26:50 +0000
Subject: Sec Bug->Bug #68900 [Opn->Nab]: Pointer use after free
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-190185@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68900&edit=1 ID: 68900 Updated by: stas@php.net Reported by: bugreports at internot dot info Summary: Pointer use after free -Status: Open +Status: Not a bug -Type: Security +Type: Bug Package: *General Issues Operating System: Linux Ubuntu 14.04 PHP Version: 5.5.21 Block user comment: N Private report: Y New Comment: zval_ptr_dtor does not always free the argument, it only frees when refcount is 1. However, SEPARATE_ARG_IF_REF() either increments the refcount or creates a copy with refcount 1, so in neither case the original "member" would be freed. Previous Comments: ------------------------------------------------------------------------ [2015-01-24 18:39:02] bugreports at internot dot info Description: ------------ Hi, In /Zend/zend_object_handlers.c: This frees 'member'("160 zval_ptr_dtor(&member);"): 470 rv = zend_std_call_getter(object, member TSRMLS_CC); but then it is used here: 487 zend_error(E_NOTICE, "Indirect modification of overloaded property %s::$%s has no effect", zobj->ce->name, Z_STRVAL_P(member)); ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=68900&edit=1

« previous php.bugs (#190185) next »