Bug #69972 [Opn]: Use-after-free vulnerability in sqlite3SafetyCheckSickOrOk()

From: Date: Fri, 10 Jul 2015 10:38:10 +0000
Subject: Bug #69972 [Opn]: Use-after-free vulnerability in sqlite3SafetyCheckSickOrOk()
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-194288@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69972&edit=1 ID: 69972 User updated by: s dot paraschoudis at gmail dot com Reported by: s dot paraschoudis at gmail dot com Summary: Use-after-free vulnerability in sqlite3SafetyCheckSickOrOk() Status: Open Type: Bug Package: SQLite related Operating System: Ubuntu 14.04.1 LTS (32 bit) PHP Version: 5.6.10 Block user comment: N Private report: Y New Comment: Updated fix by @laruence: http://git.php.net/?p=php-src.git;a=commit;h=26471eb69c3cd9e8162ff3b398d33919d9075191 Since this commit has been pushed could you please close this issue? Thanks. Previous Comments: ------------------------------------------------------------------------ [2015-06-30 20:20:55] s dot paraschoudis at gmail dot com Hey kalle, Awesome thanks, I confirm this indeed fixes the issue, AddressSanitzer is not complaining anymore. Also remi I explicitly mentioned that I couldn't reproduce the issue as well (without -fsanitize=address flag). Many thanks, Cheers. ------------------------------------------------------------------------ [2015-06-30 19:19:57] kalle@php.net Howdy, I pasted the patch from Remi here: http://pastie.org/private/hp1z7lk3gmo8r9s0glnuuw ------------------------------------------------------------------------ [2015-06-30 15:58:18] s dot paraschoudis at gmail dot com Hi remi wow that was very fast! Well I can't read the patch: You have no access to bug #69972 Care to send me via email? Thanks a lot! ------------------------------------------------------------------------ [2015-06-30 15:58:18] s dot paraschoudis at gmail dot com Related To: Bug #69972 ------------------------------------------------------------------------ [2015-06-30 15:54:04] remi@php.net Despite I cannot reproduce the segfault, probably related to memory management, can you please test it trivial attached patch solves this issue ? ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=69972 -- Edit this bug report at https://bugs.php.net/bug.php?id=69972&edit=1

« previous php.bugs (#194288) next »