Sec Bug->Bug #68900 [Opn->Nab]: Pointer use after free
| From: | stas@php.net | Date: | Sat, 24 Jan 2015 23:26:50 +0000 |
| Subject: | Sec Bug->Bug #68900 [Opn->Nab]: Pointer use after free | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-190185@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=68900&edit=1
ID: 68900
Updated by: stas@php.net
Reported by: bugreports at internot dot info
Summary: Pointer use after free
-Status: Open
+Status: Not a bug
-Type: Security
+Type: Bug
Package: *General Issues
Operating System: Linux Ubuntu 14.04
PHP Version: 5.5.21
Block user comment: N
Private report: Y
New Comment:
zval_ptr_dtor does not always free the argument, it only frees when refcount is 1. However,
SEPARATE_ARG_IF_REF() either increments the refcount or creates a copy with refcount 1, so in
neither case the original "member" would be freed.
Previous Comments:
------------------------------------------------------------------------
[2015-01-24 18:39:02] bugreports at internot dot info
Description:
------------
Hi,
In /Zend/zend_object_handlers.c:
This frees 'member'("160 zval_ptr_dtor(&member);"):
470 rv = zend_std_call_getter(object, member TSRMLS_CC);
but then it is used here:
487 zend_error(E_NOTICE, "Indirect modification
of overloaded property %s::$%s has no effect", zobj->ce->name, Z_STRVAL_P(member));
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=68900&edit=1