Bug #70863 [Csd]: Incorect logic to increment_function for proxy objects

From: Date: Sat, 07 Nov 2015 13:29:29 +0000
Subject: Bug #70863 [Csd]: Incorect logic to increment_function for proxy objects
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-197098@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70863&edit=1

 ID:                 70863
 User updated by:    jsoumelidis at gmail dot com
 Reported by:        jsoumelidis at gmail dot com
 Summary:            Incorect logic to increment_function for proxy
                     objects
 Status:             Closed
 Type:               Bug
 Package:            Reproducible crash
 Operating System:   Windows
 PHP Version:        7.0.0RC6
 Block user comment: N
 Private report:     N

 New Comment:

Same fix should be applied to functions "ZEND_TRY_BINARY_OP1_OBJECT_OPERATION"
(zend_operators.h:760) and "decrement_function" (zend_operators.c:2348)


Previous Comments:
------------------------------------------------------------------------
[2015-11-06 22:11:31] ab@php.net

Automatic comment on behalf of ab
Revision: http://git.php.net/?p=php-src.git;a=commit;h=8155ecba61a9c724c7b2bdeb673602ae27923d71
Log: Fixed bug #70863 Incorect logic to increment_function for proxy objects

------------------------------------------------------------------------
[2015-11-05 19:35:16] jsoumelidis at gmail dot com

Description:
------------
Assume you have a (custom) proxy object that one wants to increment it's value ($obj++).
If get/set object handlers are defined for this object, the "increment_function" requests
a zval* from the get handler in order to icrement it's value and assign it back to the proxy
object through the set handler.
The problem is that the increment_function executes a Z_ADDREF_P on the returned zval* from the get
handler which crashes the proccess in case the returned pointer  is not a refcounted zval.
File: zend_operators.c Line: 2280



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=70863&edit=1


Thread (4 messages)

« previous php.bugs (#197098) next »