Sec Bug->Bug #69972 [Opn]: Use-after-free vulnerability in sqlite3SafetyCheckSickOrOk()

From: Date: Sun, 05 Jul 2015 04:30:10 +0000
Subject: Sec Bug->Bug #69972 [Opn]: Use-after-free vulnerability in sqlite3SafetyCheckSickOrOk()
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-194137@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69972&edit=1 ID: 69972 Updated by: stas@php.net Reported by: s dot paraschoudis at gmail dot com Summary: Use-after-free vulnerability in sqlite3SafetyCheckSickOrOk() Status: Open -Type: Security +Type: Bug Package: SQLite related Operating System: Ubuntu 14.04.1 LTS (32 bit) PHP Version: 5.6.10 Block user comment: N Private report: Y Previous Comments: ------------------------------------------------------------------------ [2015-06-30 20:20:55] s dot paraschoudis at gmail dot com Hey kalle, Awesome thanks, I confirm this indeed fixes the issue, AddressSanitzer is not complaining anymore. Also remi I explicitly mentioned that I couldn't reproduce the issue as well (without -fsanitize=address flag). Many thanks, Cheers. ------------------------------------------------------------------------ [2015-06-30 19:19:57] kalle@php.net Howdy, I pasted the patch from Remi here: http://pastie.org/private/hp1z7lk3gmo8r9s0glnuuw ------------------------------------------------------------------------ [2015-06-30 15:58:18] s dot paraschoudis at gmail dot com Hi remi wow that was very fast! Well I can't read the patch: You have no access to bug #69972 Care to send me via email? Thanks a lot! ------------------------------------------------------------------------ [2015-06-30 15:58:18] s dot paraschoudis at gmail dot com Related To: Bug #69972 ------------------------------------------------------------------------ [2015-06-30 15:54:04] remi@php.net Despite I cannot reproduce the segfault, probably related to memory management, can you please test it trivial attached patch solves this issue ? ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=69972 -- Edit this bug report at https://bugs.php.net/bug.php?id=69972&edit=1

« previous php.bugs (#194137) next »