Bug #75867 [Com]: Freeing uninitialized pointer
| From: | philipp at redfish-solutions dot com | Date: | Wed, 24 Jan 2018 03:19:19 +0000 |
| Subject: | Bug #75867 [Com]: Freeing uninitialized pointer | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-213683@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=75867&edit=1
ID: 75867
Comment by: philipp at redfish-solutions dot com
Reported by: mike at flyn dot org
Summary: Freeing uninitialized pointer
Status: Open
Type: Bug
Package: ICONV related
Operating System: Linux
PHP Version: 7.2.1
Block user comment: N
Private report: N
New Comment:
One path through the conditional code of php_iconv_string() NULL's the pointer *out. The other
path doesn't. This seems broken, or at the very least, extremely risky.
NULL it out on either path so that if we bail early on an error condition, it's consistently
set the same.
Previous Comments:
------------------------------------------------------------------------
[2018-01-24 02:51:31] mike at flyn dot org
Description:
------------
In iconv.c, it is possible that out_buffer might be free'd without every having been made to
point to a valid heap address. This is because stack variables are not implicitly initialized, and
php_iconv_string might fail, thus never initializing &out_buffer.
See the attached patch.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=75867&edit=1