Bug #73549 [Csd]: Use after free when stream is passed to imagepng

From: Date: Thu, 01 Dec 2016 11:42:52 +0000
Subject: Bug #73549 [Csd]: Use after free when stream is passed to imagepng
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-205708@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73549&edit=1 ID: 73549 Updated by: cmb@php.net Reported by: marceloje at gmail dot com Summary: Use after free when stream is passed to imagepng Status: Closed Type: Bug Package: GD related Operating System: Linux x86_64 PHP Version: 5.6.28 Assigned To: cmb Block user comment: N Private report: N New Comment: Actually, I would have chosen _php_image_stream_ctx_free and _php_image_stream_ctx_free_and_close, but as there already was _php_image_stream_ctxfree I tried to be consistent. Previous Comments: ------------------------------------------------------------------------ [2016-11-30 23:43:30] yohgaki@php.net It's static function. It does not matter much, but isn't _php_image_stream_ctxfree_and_close() or _php_image_stream_ctxfree_close are better than _php_image_stream_ctxfreeandclose() ------------------------------------------------------------------------ [2016-11-30 23:13:54] davey@php.net Automatic comment on behalf of cmbecker69@gmx.de Revision: http://git.php.net/?p=php-src.git;a=commit;h=5049ef2f1c496c4964cd147e185c1f765ab0347b Log: Fix #73549: Use after free when stream is passed to imagepng ------------------------------------------------------------------------ [2016-11-27 22:49:41] stas@php.net My bad, it works. ------------------------------------------------------------------------ [2016-11-27 11:06:56] cmb@php.net I've just applied the patch against current PHP-5.6 head, and the test succeeds. The test failure you're getting is expected *without* the patch. Note that there's a build flaw in ext/gd where changes to gd_ctx.c (and other source files) don't trigger re-compilation of gd.(l)o. In other words, if you already have built PHP-5.6, apply the patch and do only make, the test failure is to be expected. ------------------------------------------------------------------------ [2016-11-26 22:54:37] stas@php.net For me the test does not work: 002+ resource(5) of type (Unknown) 002- resource(%d) of type (stream) Could you please check? ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=73549 -- Edit this bug report at https://bugs.php.net/bug.php?id=73549&edit=1

« previous php.bugs (#205708) next »