Bug #70183 [Csd]: null pointer deref (segfault) in zend_eval_const_expr

From: Date: Sun, 02 Aug 2015 19:25:42 +0000
Subject: Bug #70183 [Csd]: null pointer deref (segfault) in zend_eval_const_expr
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-194909@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70183&edit=1 ID: 70183 User updated by: hugh at allthethings dot co dot nz Reported by: hugh at allthethings dot co dot nz Summary: null pointer deref (segfault) in zend_eval_const_expr Status: Closed Type: Bug Package: Reproducible crash Operating System: Linux PHP Version: master-Git-2015-08-02 (Git) Assigned To: ab Block user comment: N Private report: N New Comment: I was basing the security flag of a similar one like bug #68618 Previous Comments: ------------------------------------------------------------------------ [2015-08-02 19:23:41] hugh at allthethings dot co dot nz Hey, Thanks for the quick fix. No worries about the security flag, wasn't sure. Started fuzzing on 5.6 as well, so hopefully more there :D. Would any crashes count as security on pre-release? Cheers, Hugh ------------------------------------------------------------------------ [2015-08-02 15:36:13] ab@php.net Patch applied in 2a1a8f9ea75d4c8c9c47c2a391113764b9d0639b. Btw not sure if it makes sense to file security bugs for some pre release. Thanks. ------------------------------------------------------------------------ [2015-08-02 09:38:28] hugh at allthethings dot co dot nz Related To: Bug #70183 ------------------------------------------------------------------------ [2015-08-02 09:38:28] hugh at allthethings dot co dot nz Related To: Bug #70183 ------------------------------------------------------------------------ [2015-08-02 09:38:27] hugh at allthethings dot co dot nz Won't let me upload patch for some reason, says still private. See below. Author: Hugh Davenport <hugh@allthethings.co.nz> Date: Sun Aug 2 05:35:25 2015 -0400 Fix bug #70183 (null pointer deref (segfault) in zend_eval_const_expr) diff --git a/Zend/tests/bug70183.phpt b/Zend/tests/bug70183.phpt new file mode 100644 index 0000000..4b038fd --- /dev/null +++ b/Zend/tests/bug70183.phpt @@ -0,0 +1,8 @@ +--TEST-- +Bug #70183 (null pointer deref (segfault) in zend_eval_const_expr) +--FILE-- +<?php +[[][]] +?> +--EXPECTF-- +Fatal error: Cannot use [] for reading in %sbug70182.php on line 2 diff --git a/Zend/zend_compile.c b/Zend/zend_compile.c index 5d7eec2..0e9f478 100644 --- a/Zend/zend_compile.c +++ b/Zend/zend_compile.c @@ -7374,7 +7374,7 @@ void zend_eval_const_expr(zend_ast **ast_ptr) /* {{{ */ zend_eval_const_expr(&ast->child[0]); zend_eval_const_expr(&ast->child[1]); - if (ast->child[0]->kind != ZEND_AST_ZVAL || ast->child[1]->kind != ZEND_AST_ZVAL) { + if (!ast->child[0] || !ast->child[1] || ast->child[0]->kind != ZEND_AST_ZVAL || ast->child[1]->kind != ZEND_AST_ZVAL) { return; } ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=70183 -- Edit this bug report at https://bugs.php.net/bug.php?id=70183&edit=1

« previous php.bugs (#194909) next »