Bug #71729 [Opn->Csd]: Possible crash in zend_bin_strtod, zend_oct_strtod, zend_hex_strtod

From: Date: Wed, 09 Mar 2016 04:17:03 +0000
Subject: Bug #71729 [Opn->Csd]: Possible crash in zend_bin_strtod, zend_oct_strtod, zend_hex_strtod
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-199686@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71729&edit=1 ID: 71729 Updated by: laruence@php.net Reported by: temp at temp dot ru Summary: Possible crash in zend_bin_strtod, zend_oct_strtod, zend_hex_strtod -Status: Open +Status: Closed Type: Bug Package: *General Issues PHP Version: 7.0.4 Block user comment: N Private report: N New Comment: Automatic comment on behalf of laruence@gmail.com Revision: http://git.php.net/?p=php-src.git;a=commit;h=9aa73d38000b9bb9de8dc8aa96e7dcef30506202 Log: Fixed bug #71729 (Possible crash in zend_bin_strtod, zend_oct_strtod, zend_hex_strtod) Previous Comments: ------------------------------------------------------------------------ [2016-03-07 11:12:15] temp at temp dot ru Description: ------------ These three function has a flaw that can eventually result in crash: ZEND_API double zend_bin_strtod(const char *str, const char **endptr) { ... if (strlen(str) < 2) { *endptr = str; <--- No check if endptr is NULL, can result in zero pointer dereferencing return 0.0; } ... if (NULL != endptr) { <--- But here this check is present *endptr = (char *)(any ? s - 1 : str); } return value; } ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=71729&edit=1

« previous php.bugs (#199686) next »