Bug #68717 [Opn->Nab]: use after free
| From: | cmb@php.net | Date: | Sat, 23 Jul 2016 15:20:24 +0000 |
| Subject: | Bug #68717 [Opn->Nab]: use after free | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-202530@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=68717&edit=1
ID: 68717
Updated by: cmb@php.net
Reported by: bugreports at internot dot info
Summary: use after free
-Status: Open
+Status: Not a bug
Type: Bug
Package: GD related
Operating System: Linux Ubuntu 14.04
PHP Version: master-Git-2015-01-02 (Git)
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Indeed. Thanks!
Previous Comments:
------------------------------------------------------------------------
[2016-05-27 15:37:16] php at mcq8 dot be
If the gdRealloc fails, the 'dp->data' is untouched
(http://linux.die.net/man/3/realloc).
So this is not a bug and should be closed.
------------------------------------------------------------------------
[2015-01-02 08:43:17] bugreports at internot dot info
Description:
------------
Hi,
In /ext/gd/libgd/gd_io_dp.c:
if this goes to the false branch:
333 if ((newPtr = gdRealloc(dp->data, required))) {
334 dp->realSize = required;
335 dp->data = newPtr;
336 return TRUE;
337 }
the fact there is code after this, makes me think it is possible for this to happen:
'dp->data' will be freed but not re-allocated.
It is then used here:
343 memcpy(newPtr, dp->data, dp->logicalSize);
which will cause a use-after-free bug.
Thanks,
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=68717&edit=1