Bug #68717 [Com]: use after free
| From: | php at mcq8 dot be | Date: | Fri, 27 May 2016 15:37:19 +0000 |
| Subject: | Bug #68717 [Com]: use after free | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-201297@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=68717&edit=1
ID: 68717
Comment by: php at mcq8 dot be
Reported by: bugreports at internot dot info
Summary: use after free
Status: Open
Type: Bug
Package: GD related
Operating System: Linux Ubuntu 14.04
PHP Version: master-Git-2015-01-02 (Git)
Block user comment: N
Private report: N
New Comment:
If the gdRealloc fails, the 'dp->data' is untouched
(http://linux.die.net/man/3/realloc).
So this is not a bug and should be closed.
Previous Comments:
------------------------------------------------------------------------
[2015-01-02 08:43:17] bugreports at internot dot info
Description:
------------
Hi,
In /ext/gd/libgd/gd_io_dp.c:
if this goes to the false branch:
333 if ((newPtr = gdRealloc(dp->data, required))) {
334 dp->realSize = required;
335 dp->data = newPtr;
336 return TRUE;
337 }
the fact there is code after this, makes me think it is possible for this to happen:
'dp->data' will be freed but not re-allocated.
It is then used here:
343 memcpy(newPtr, dp->data, dp->logicalSize);
which will cause a use-after-free bug.
Thanks,
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=68717&edit=1