Bug #70183 [Csd]: null pointer deref (segfault) in zend_eval_const_expr
| From: | hugh at allthethings dot co dot nz | Date: | Sun, 02 Aug 2015 19:25:42 +0000 |
| Subject: | Bug #70183 [Csd]: null pointer deref (segfault) in zend_eval_const_expr | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-194909@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=70183&edit=1
ID: 70183
User updated by: hugh at allthethings dot co dot nz
Reported by: hugh at allthethings dot co dot nz
Summary: null pointer deref (segfault) in
zend_eval_const_expr
Status: Closed
Type: Bug
Package: Reproducible crash
Operating System: Linux
PHP Version: master-Git-2015-08-02 (Git)
Assigned To: ab
Block user comment: N
Private report: N
New Comment:
I was basing the security flag of a similar one like bug #68618
Previous Comments:
------------------------------------------------------------------------
[2015-08-02 19:23:41] hugh at allthethings dot co dot nz
Hey,
Thanks for the quick fix.
No worries about the security flag, wasn't sure. Started fuzzing on 5.6 as well, so hopefully
more there :D.
Would any crashes count as security on pre-release?
Cheers,
Hugh
------------------------------------------------------------------------
[2015-08-02 15:36:13] ab@php.net
Patch applied in 2a1a8f9ea75d4c8c9c47c2a391113764b9d0639b. Btw not sure if it makes sense to file
security bugs for some pre release.
Thanks.
------------------------------------------------------------------------
[2015-08-02 09:38:28] hugh at allthethings dot co dot nz
Related To: Bug #70183
------------------------------------------------------------------------
[2015-08-02 09:38:28] hugh at allthethings dot co dot nz
Related To: Bug #70183
------------------------------------------------------------------------
[2015-08-02 09:38:27] hugh at allthethings dot co dot nz
Won't let me upload patch for some reason, says still private. See below.
Author: Hugh Davenport <hugh@allthethings.co.nz>
Date: Sun Aug 2 05:35:25 2015 -0400
Fix bug #70183 (null pointer deref (segfault) in zend_eval_const_expr)
diff --git a/Zend/tests/bug70183.phpt b/Zend/tests/bug70183.phpt
new file mode 100644
index 0000000..4b038fd
--- /dev/null
+++ b/Zend/tests/bug70183.phpt
@@ -0,0 +1,8 @@
+--TEST--
+Bug #70183 (null pointer deref (segfault) in zend_eval_const_expr)
+--FILE--
+<?php
+[[][]]
+?>
+--EXPECTF--
+Fatal error: Cannot use [] for reading in %sbug70182.php on line 2
diff --git a/Zend/zend_compile.c b/Zend/zend_compile.c
index 5d7eec2..0e9f478 100644
--- a/Zend/zend_compile.c
+++ b/Zend/zend_compile.c
@@ -7374,7 +7374,7 @@ void zend_eval_const_expr(zend_ast **ast_ptr) /* {{{ */
zend_eval_const_expr(&ast->child[0]);
zend_eval_const_expr(&ast->child[1]);
- if (ast->child[0]->kind != ZEND_AST_ZVAL || ast->child[1]->kind
!= ZEND_AST_ZVAL) {
+ if (!ast->child[0] || !ast->child[1] || ast->child[0]->kind !=
ZEND_AST_ZVAL || ast->child[1]->kind != ZEND_AST_ZVAL) {
return;
}
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=70183
--
Edit this bug report at https://bugs.php.net/bug.php?id=70183&edit=1