Bug #68717 [Com]: use after free

From: Date: Fri, 27 May 2016 15:37:19 +0000
Subject: Bug #68717 [Com]: use after free
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-201297@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68717&edit=1 ID: 68717 Comment by: php at mcq8 dot be Reported by: bugreports at internot dot info Summary: use after free Status: Open Type: Bug Package: GD related Operating System: Linux Ubuntu 14.04 PHP Version: master-Git-2015-01-02 (Git) Block user comment: N Private report: N New Comment: If the gdRealloc fails, the 'dp->data' is untouched (http://linux.die.net/man/3/realloc). So this is not a bug and should be closed. Previous Comments: ------------------------------------------------------------------------ [2015-01-02 08:43:17] bugreports at internot dot info Description: ------------ Hi, In /ext/gd/libgd/gd_io_dp.c: if this goes to the false branch: 333 if ((newPtr = gdRealloc(dp->data, required))) { 334 dp->realSize = required; 335 dp->data = newPtr; 336 return TRUE; 337 } the fact there is code after this, makes me think it is possible for this to happen: 'dp->data' will be freed but not re-allocated. It is then used here: 343 memcpy(newPtr, dp->data, dp->logicalSize); which will cause a use-after-free bug. Thanks, ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=68717&edit=1

« previous php.bugs (#201297) next »