Bug #72399 [Csd]: Use-After-Free in MBString (search_re)
| From: | shm@php.net | Date: | Tue, 14 Jun 2016 08:28:43 +0000 |
| Subject: | Bug #72399 [Csd]: Use-After-Free in MBString (search_re) | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-201591@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=72399&edit=1
ID: 72399
Updated by: shm@php.net
Reported by: shm@php.net
Summary: Use-After-Free in MBString (search_re)
Status: Closed
Type: Bug
Package: mbstring related
PHP Version: 7.0Git-2016-06-13 (Git)
Assigned To: laruence
Block user comment: N
Private report: N
New Comment:
Thanks for the clarification. Still, shown code pattern could be used in popular script, thus it
would let to perform attack from the remote.
I don't want to force this bug (or any other as a security issue), but I'm just a little
bit confused - what's the difference between this one and https://bugs.php.net/bug.php?id=72093 this one for
example.
Previous Comments:
------------------------------------------------------------------------
[2016-06-14 07:57:34] stas@php.net
Yes, we do. Issues that require local access to trigger do not considered as a rule security issues,
since once you can run code on a local host, you can do anything anyway.
------------------------------------------------------------------------
[2016-06-14 06:32:25] shm@php.net
I'm not sure what we consider as a security issue. Previously bugs like this one were marked as
security bugs (it can be used to bypass disable_functions upon code execution is done, potentially
code to trigger that issue could be also present in popular script). Do we have any policy on this
subject?
------------------------------------------------------------------------
[2016-06-14 01:20:46] laruence@php.net
Automatic comment on behalf of laruence@gmail.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=3d5641872239cbd4ec8855b05c90f94fb0d11d7e
Log: Fixed bug #72399 (Use-After-Free in MBString (search_re))
------------------------------------------------------------------------
[2016-06-14 01:17:51] laruence@php.net
this is not a security issue, as you need specially codes to trigger it
------------------------------------------------------------------------
[2016-06-13 20:34:51] shm@php.net
7.1 -> 7.0
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=72399
--
Edit this bug report at https://bugs.php.net/bug.php?id=72399&edit=1