Bug #67857 [Com]: PHP natsort() use-after-free / memory corruption
| From: | spam2 at rhsoft dot net | Date: | Thu, 16 Mar 2017 21:15:46 +0000 |
| Subject: | Bug #67857 [Com]: PHP natsort() use-after-free / memory corruption | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-207884@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=67857&edit=1
ID: 67857
Comment by: spam2 at rhsoft dot net
Reported by: andrea dot palazzo at truel dot it
Summary: PHP natsort() use-after-free / memory corruption
Status: Open
Type: Bug
Package: Arrays related
PHP Version: Irrelevant
Block user comment: N
Private report: N
New Comment:
the point is that memory corruption often opens gates where you don't need to execurte
high-level php-code when you can compromise the whole webserver process
Previous Comments:
------------------------------------------------------------------------
[2017-03-16 21:05:46] nikic@php.net
@rhsoft: Please see our security policy at https://wiki.php.net/security. If you still feel that this
is a security issue *under the restrictions outlined therein*, please explain in more detail why
this is the case. If you disagree with the security policy itself, please start a discussion on the
PHP internals mailing list.
------------------------------------------------------------------------
[2017-03-16 20:42:47] spam2 at rhsoft dot net
i would be careful with "as there is no remote exploitation vector -- ability to locally
execute PHP code is required" in case of memory corruption and qualify something as remote
exploitation vector!
------------------------------------------------------------------------
[2017-03-16 20:34:21] nikic@php.net
Removing security classification, as there is no remote exploitation vector -- ability to locally
execute PHP code is required.
------------------------------------------------------------------------
[2015-07-03 07:13:50] andrea dot palazzo at truel dot it
Just spotted the typo in the title
------------------------------------------------------------------------
[2015-07-01 17:42:20] andrea dot palazzo at truel dot it
Hello guys,
any update on this one?
Also, around the same period I submitted via e-mail a similar issue in extract() but I can't
find the entry here in the bug track, should I repost it?
Regards,
Andrea
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=67857
--
Edit this bug report at https://bugs.php.net/bug.php?id=67857&edit=1