Bug #75420 [Ver->Csd]: Crash when modifing property name in __isset for BP_VAR_IS
| From: | laruence@php.net | Date: | Thu, 26 Oct 2017 02:19:57 +0000 |
| Subject: | Bug #75420 [Ver->Csd]: Crash when modifing property name in __isset for BP_VAR_IS | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-212322@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=75420&edit=1
ID: 75420
Updated by: laruence@php.net
Reported by: nikic@php.net
Summary: Crash when modifing property name in __isset for
BP_VAR_IS
-Status: Verified
+Status: Closed
Type: Bug
Package: Scripting Engine problem
PHP Version: 7.0.24
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of laruence@gmail.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=d2047503cbc080ef96b00ac254604aaa01cf618e
Log: Fixed bug #75420 (Crash when modifing property name in __isset for BP_VAR_IS)
Previous Comments:
------------------------------------------------------------------------
[2017-10-23 20:00:06] nikic@php.net
Description:
------------
$name is changed from string to int in the __isset() call, so that the subsequent __get() call
crashes.
Test script:
---------------
<?php
class Test {
public function __isset($x) { $GLOBALS['name'] = 24; return true; }
public function __get($x) { var_dump($x); return 42; }
}
$obj = new Test;
$name = "foo";
var_dump($obj->$name ?? 12);
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=75420&edit=1