Bug #75867 [Com]: Freeing uninitialized pointer

From: Date: Wed, 24 Jan 2018 03:19:19 +0000
Subject: Bug #75867 [Com]: Freeing uninitialized pointer
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-213683@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=75867&edit=1 ID: 75867 Comment by: philipp at redfish-solutions dot com Reported by: mike at flyn dot org Summary: Freeing uninitialized pointer Status: Open Type: Bug Package: ICONV related Operating System: Linux PHP Version: 7.2.1 Block user comment: N Private report: N New Comment: One path through the conditional code of php_iconv_string() NULL's the pointer *out. The other path doesn't. This seems broken, or at the very least, extremely risky. NULL it out on either path so that if we bail early on an error condition, it's consistently set the same. Previous Comments: ------------------------------------------------------------------------ [2018-01-24 02:51:31] mike at flyn dot org Description: ------------ In iconv.c, it is possible that out_buffer might be free'd without every having been made to point to a valid heap address. This is because stack variables are not implicitly initialized, and php_iconv_string might fail, thus never initializing &out_buffer. See the attached patch. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=75867&edit=1

« previous php.bugs (#213683) next »