Bug #46948 [Asn]: ext/date/lib/parse_tz.c:99: Memory leak: buffer

From: Date: Wed, 11 Jan 2017 16:33:45 +0000
Subject: Bug #46948 [Asn]: ext/date/lib/parse_tz.c:99: Memory leak: buffer
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-206525@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=46948&edit=1

 ID:                 46948
 Updated by:         heiglandreas@php.net
 Reported by:        dvice_null at yahoo dot com
 Summary:            ext/date/lib/parse_tz.c:99: Memory leak: buffer
 Status:             Assigned
 Type:               Bug
 Package:            Date/time related
 Operating System:   *
 PHP Version:        6CVS-2008-12-26 (CVS)
 Assigned To:        derick
 Block user comment: N
 Private report:     N

 New Comment:

Is this still an issue? Or can that be closed after 8 years and targeting an unsupported version?


Previous Comments:
------------------------------------------------------------------------
[2008-12-26 21:59:27] felipe@php.net

Truly, I think that Derick really free that vars. in another place.

------------------------------------------------------------------------
[2008-12-26 21:51:44] felipe@php.net

I think something like this:

Index: ext/date/lib/parse_tz.c
===================================================================
RCS file: /repository/php-src/ext/date/lib/parse_tz.c,v
retrieving revision 1.20.2.6.2.13.2.4
diff -u -p -r1.20.2.6.2.13.2.4 parse_tz.c
--- ext/date/lib/parse_tz.c	9 Aug 2008 22:01:08 -0000	1.20.2.6.2.13.2.4
+++ ext/date/lib/parse_tz.c	26 Dec 2008 21:47:20 -0000
@@ -100,6 +100,7 @@ static void read_transistions(char **tzf
 
 		cbuffer = (unsigned char*) malloc(tz->timecnt * sizeof(unsigned char));
 		if (!cbuffer) {
+			free(buffer);
 			return;
 		}
 		memcpy(cbuffer, *tzf, sizeof(unsigned char) * tz->timecnt);
@@ -125,6 +126,7 @@ static void read_types(char **tzf, timel
 
 	tz->type = (ttinfo*) malloc(tz->typecnt * sizeof(struct ttinfo));
 	if (!tz->type) {
+		free(buffer);
 		return;
 	}
 
@@ -153,6 +155,9 @@ static void read_types(char **tzf, timel
 
 		tz->leap_times = (tlinfo*) malloc(tz->leapcnt * sizeof(tlinfo));
 		if (!tz->leap_times) {
+			free(leap_buffer);
+			free(tz->timezone_abbr);
+			free(tz->types);
 			return;
 		}
 		for (i = 0; i < tz->leapcnt; i++) {


------------------------------------------------------------------------
[2008-12-26 21:11:53] dvice_null at yahoo dot com

Two similar problems in the same file. Let me know if you want separate bug reports about these:

----------------

ext/date/lib/parse_tz.c:124]: Memory leak: buffer

if (!tz->type) {
  return;
}

----------------

ext/date/lib/parse_tz.c:152: Memory leak: leap_buffer

if (!tz->leap_times) {
  return;
}

------------------------------------------------------------------------
[2008-12-26 20:55:43] dvice_null at yahoo dot com

Description:
------------
In file ext/date/lib/parse_tz.c:99: 
Variable "buffer" leaks memory if "cbuffer" is null in this code:

if (!cbuffer) {
  return;
}


This bug was found using cppcheck: http://cppcheck.wiki.sourceforge.net/



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=46948&edit=1


Thread (6 messages)

« previous php.bugs (#206525) next »