Bug #68676 [Com]: Explicit Double Free
| From: | paul at ifdnrg dot com | Date: | Fri, 31 Jul 2015 11:52:24 +0000 |
| Subject: | Bug #68676 [Com]: Explicit Double Free | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-194862@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=68676&edit=1
ID: 68676
Comment by: paul at ifdnrg dot com
Reported by: bugreports at internot dot info
Summary: Explicit Double Free
Status: Closed
Type: Bug
Package: *General Issues
Operating System: Linux Ubuntu 14.04
PHP Version: master-Git-2014-12-29 (Git)
Assigned To: kalle
Block user comment: N
Private report: N
CVE-ID: 2014-9425
New Comment:
Whilst this is marked as closed, the CVE entry is still open and its getting picked by PCI
compliance tests (trustwave)
I can still see the double free in the git src.
Previous Comments:
------------------------------------------------------------------------
[2014-12-31 01:03:08] kalle@php.net
Honestly there is not really, as the TsHash API is barely used, and the only place I spotted a
zend_ts_hash_init call was in ext/com_dotnet which is Windows only
------------------------------------------------------------------------
[2014-12-30 23:38:34] bugreports at internot dot info
Is a testcase available for this, by the way?
Thanks,
------------------------------------------------------------------------
[2014-12-30 09:28:16] stas@php.net
Automatic comment on behalf of kalle
Revision: http://git.php.net/?p=php-src.git;a=commit;h=24125f0f26f3787c006e4a51611ba33ee3b841cb
Log: Fixed bug #68676 (Explicit Double Free)
------------------------------------------------------------------------
[2014-12-30 09:28:14] stas@php.net
Automatic comment on behalf of kalle
Revision: http://git.php.net/?p=php-src.git;a=commit;h=fbf3a6bc1abcc8a5b5226b0ad9464c37f11ddbd6
Log: Fixed bug #68676 (Explicit Double Free)
------------------------------------------------------------------------
[2014-12-29 10:04:42] kalle@php.net
Automatic comment on behalf of kalle
Revision: http://git.php.net/?p=php-src.git;a=commit;h=fbf3a6bc1abcc8a5b5226b0ad9464c37f11ddbd6
Log: Fixed bug #68676 (Explicit Double Free)
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=68676
--
Edit this bug report at https://bugs.php.net/bug.php?id=68676&edit=1