Bug #68717 [Opn->Nab]: use after free

From: Date: Sat, 23 Jul 2016 15:20:24 +0000
Subject: Bug #68717 [Opn->Nab]: use after free
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-202530@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68717&edit=1 ID: 68717 Updated by: cmb@php.net Reported by: bugreports at internot dot info Summary: use after free -Status: Open +Status: Not a bug Type: Bug Package: GD related Operating System: Linux Ubuntu 14.04 PHP Version: master-Git-2015-01-02 (Git) -Assigned To: +Assigned To: cmb Block user comment: N Private report: N New Comment: Indeed. Thanks! Previous Comments: ------------------------------------------------------------------------ [2016-05-27 15:37:16] php at mcq8 dot be If the gdRealloc fails, the 'dp->data' is untouched (http://linux.die.net/man/3/realloc). So this is not a bug and should be closed. ------------------------------------------------------------------------ [2015-01-02 08:43:17] bugreports at internot dot info Description: ------------ Hi, In /ext/gd/libgd/gd_io_dp.c: if this goes to the false branch: 333 if ((newPtr = gdRealloc(dp->data, required))) { 334 dp->realSize = required; 335 dp->data = newPtr; 336 return TRUE; 337 } the fact there is code after this, makes me think it is possible for this to happen: 'dp->data' will be freed but not re-allocated. It is then used here: 343 memcpy(newPtr, dp->data, dp->logicalSize); which will cause a use-after-free bug. Thanks, ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=68717&edit=1

« previous php.bugs (#202530) next »