Bug #75867 [Opn->Csd]: Freeing uninitialized pointer
| From: | cmb@php.net | Date: | Sat, 24 Feb 2018 22:29:45 +0000 |
| Subject: | Bug #75867 [Opn->Csd]: Freeing uninitialized pointer | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-214100@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=75867&edit=1
ID: 75867
Updated by: cmb@php.net
Reported by: mike at flyn dot org
Summary: Freeing uninitialized pointer
-Status: Open
+Status: Closed
Type: Bug
Package: ICONV related
Operating System: Linux
PHP Version: 7.2.1
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
This issue has been resolved by merging
<https://github.com/php/php-src/pull/3037>.
Previous Comments:
------------------------------------------------------------------------
[2018-01-24 03:19:17] philipp at redfish-solutions dot com
One path through the conditional code of php_iconv_string() NULL's the pointer *out. The other
path doesn't. This seems broken, or at the very least, extremely risky.
NULL it out on either path so that if we bail early on an error condition, it's consistently
set the same.
------------------------------------------------------------------------
[2018-01-24 02:51:31] mike at flyn dot org
Description:
------------
In iconv.c, it is possible that out_buffer might be free'd without every having been made to
point to a valid heap address. This is because stack variables are not implicitly initialized, and
php_iconv_string might fail, thus never initializing &out_buffer.
See the attached patch.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=75867&edit=1