Bug #72828 [Asn]: php_strtr_array_prepare_repls does not check allocation results

From: Date: Sat, 13 Aug 2016 12:05:24 +0000
Subject: Bug #72828 [Asn]: php_strtr_array_prepare_repls does not check allocation results
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-203238@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72828&edit=1 ID: 72828 Updated by: nikic@php.net Reported by: cmb@php.net Summary: php_strtr_array_prepare_repls does not check allocation results Status: Assigned Type: Bug Package: Strings related Operating System: * PHP Version: 5.6Git-2016-08-13 (Git) Assigned To: cmb Block user comment: N Private report: N New Comment: Unless the allocations explicitly use the system allocator (i.e. do not use emalloc and variants), do NOT introduce NULL checks. Previous Comments: ------------------------------------------------------------------------ [2016-08-13 11:45:36] cmb@php.net Description: ------------ In php_strtr_array_prepare_repls() patterns and *allocs are allocated on the heap, but it is not checked whether that might have failed, what can lead to OOB writes. This may not be a problem with the Zend MM, but can be with other memory managers. If that also affects PHP 7 (where strtr() had be reimplemented), has to be checked. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=72828&edit=1

« previous php.bugs (#203238) next »