Bug #75867 [Opn->Csd]: Freeing uninitialized pointer

From: Date: Sat, 24 Feb 2018 22:29:45 +0000
Subject: Bug #75867 [Opn->Csd]: Freeing uninitialized pointer
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-214100@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=75867&edit=1 ID: 75867 Updated by: cmb@php.net Reported by: mike at flyn dot org Summary: Freeing uninitialized pointer -Status: Open +Status: Closed Type: Bug Package: ICONV related Operating System: Linux PHP Version: 7.2.1 -Assigned To: +Assigned To: cmb Block user comment: N Private report: N New Comment: This issue has been resolved by merging <https://github.com/php/php-src/pull/3037>. Previous Comments: ------------------------------------------------------------------------ [2018-01-24 03:19:17] philipp at redfish-solutions dot com One path through the conditional code of php_iconv_string() NULL's the pointer *out. The other path doesn't. This seems broken, or at the very least, extremely risky. NULL it out on either path so that if we bail early on an error condition, it's consistently set the same. ------------------------------------------------------------------------ [2018-01-24 02:51:31] mike at flyn dot org Description: ------------ In iconv.c, it is possible that out_buffer might be free'd without every having been made to point to a valid heap address. This is because stack variables are not implicitly initialized, and php_iconv_string might fail, thus never initializing &out_buffer. See the attached patch. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=75867&edit=1

« previous php.bugs (#214100) next »