Bug #67857 [Com]: PHP natsort() use-after-free / memory corruption

From: Date: Thu, 16 Mar 2017 21:15:46 +0000
Subject: Bug #67857 [Com]: PHP natsort() use-after-free / memory corruption
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-207884@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=67857&edit=1 ID: 67857 Comment by: spam2 at rhsoft dot net Reported by: andrea dot palazzo at truel dot it Summary: PHP natsort() use-after-free / memory corruption Status: Open Type: Bug Package: Arrays related PHP Version: Irrelevant Block user comment: N Private report: N New Comment: the point is that memory corruption often opens gates where you don't need to execurte high-level php-code when you can compromise the whole webserver process Previous Comments: ------------------------------------------------------------------------ [2017-03-16 21:05:46] nikic@php.net @rhsoft: Please see our security policy at https://wiki.php.net/security. If you still feel that this is a security issue *under the restrictions outlined therein*, please explain in more detail why this is the case. If you disagree with the security policy itself, please start a discussion on the PHP internals mailing list. ------------------------------------------------------------------------ [2017-03-16 20:42:47] spam2 at rhsoft dot net i would be careful with "as there is no remote exploitation vector -- ability to locally execute PHP code is required" in case of memory corruption and qualify something as remote exploitation vector! ------------------------------------------------------------------------ [2017-03-16 20:34:21] nikic@php.net Removing security classification, as there is no remote exploitation vector -- ability to locally execute PHP code is required. ------------------------------------------------------------------------ [2015-07-03 07:13:50] andrea dot palazzo at truel dot it Just spotted the typo in the title ------------------------------------------------------------------------ [2015-07-01 17:42:20] andrea dot palazzo at truel dot it Hello guys, any update on this one? Also, around the same period I submitted via e-mail a similar issue in extract() but I can't find the entry here in the bug track, should I repost it? Regards, Andrea ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=67857 -- Edit this bug report at https://bugs.php.net/bug.php?id=67857&edit=1

« previous php.bugs (#207884) next »