Bug #70863 [Opn->Csd]: Incorect logic to increment_function for proxy objects
Edit report at https://bugs.php.net/bug.php?id=70863&edit=1
ID: 70863
Updated by: ab@php.net
Reported by: jsoumelidis at gmail dot com
Summary: Incorect logic to increment_function for proxy
objects
-Status: Open
+Status: Closed
Type: Bug
Package: Reproducible crash
Operating System: Windows
PHP Version: 7.0.0RC6
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of ab
Revision: http://git.php.net/?p=php-src.git;a=commit;h=8155ecba61a9c724c7b2bdeb673602ae27923d71
Log: Fixed bug #70863 Incorect logic to increment_function for proxy objects
Previous Comments:
------------------------------------------------------------------------
[2015-11-05 19:35:16] jsoumelidis at gmail dot com
Description:
------------
Assume you have a (custom) proxy object that one wants to increment it's value ($obj++).
If get/set object handlers are defined for this object, the "increment_function" requests
a zval* from the get handler in order to icrement it's value and assign it back to the proxy
object through the set handler.
The problem is that the increment_function executes a Z_ADDREF_P on the returned zval* from the get
handler which crashes the proccess in case the returned pointer is not a refcounted zval.
File: zend_operators.c Line: 2280
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=70863&edit=1
Thread (4 messages)