Bug #70183 [Csd]: null pointer deref (segfault) in zend_eval_const_expr

From: Date: Sun, 02 Aug 2015 20:31:12 +0000
Subject: Bug #70183 [Csd]: null pointer deref (segfault) in zend_eval_const_expr
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-194912@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70183&edit=1 ID: 70183 User updated by: hugh at allthethings dot co dot nz Reported by: hugh at allthethings dot co dot nz Summary: null pointer deref (segfault) in zend_eval_const_expr Status: Closed Type: Bug Package: Reproducible crash Operating System: Linux PHP Version: master-Git-2015-08-02 (Git) Assigned To: ab Block user comment: N Private report: N New Comment: Cool, makes sense. I've got a few more 7.0 ones to submit and some 5.6 ones as well. Changed fuzzing focus to 5.6 for a few days. Previous Comments: ------------------------------------------------------------------------ [2015-08-02 20:26:46] ab@php.net Hugh, #68618 was switched to security, after it turned out it is in a stable branch (5.6) as well. Any crash is a stable branch should be security. But a pre release is explicitly not for production, so ATM - if it's 7.0 only crash, no need for security. Once 7.0 is GA - yes, it's security in any case. Thanks. ------------------------------------------------------------------------ [2015-08-02 19:25:42] hugh at allthethings dot co dot nz I was basing the security flag of a similar one like bug #68618 ------------------------------------------------------------------------ [2015-08-02 19:23:41] hugh at allthethings dot co dot nz Hey, Thanks for the quick fix. No worries about the security flag, wasn't sure. Started fuzzing on 5.6 as well, so hopefully more there :D. Would any crashes count as security on pre-release? Cheers, Hugh ------------------------------------------------------------------------ [2015-08-02 15:36:13] ab@php.net Patch applied in 2a1a8f9ea75d4c8c9c47c2a391113764b9d0639b. Btw not sure if it makes sense to file security bugs for some pre release. Thanks. ------------------------------------------------------------------------ [2015-08-02 09:38:28] hugh at allthethings dot co dot nz Related To: Bug #70183 ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=70183 -- Edit this bug report at https://bugs.php.net/bug.php?id=70183&edit=1

« previous php.bugs (#194912) next »