Bug #71729 [Csd]: Possible crash in zend_bin_strtod, zend_oct_strtod, zend_hex_strtod

From: Date: Fri, 23 Nov 2018 09:22:04 +0000
Subject: Bug #71729 [Csd]: Possible crash in zend_bin_strtod, zend_oct_strtod, zend_hex_strtod
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-218095@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71729&edit=1 ID: 71729 User updated by: dragondreamer at live dot com Reported by: dragondreamer at live dot com Summary: Possible crash in zend_bin_strtod, zend_oct_strtod, zend_hex_strtod Status: Closed Type: Bug Package: *General Issues PHP Version: 7.0.4 Block user comment: N Private report: N New Comment: Edit e-mail address Previous Comments: ------------------------------------------------------------------------ [2016-07-20 11:33:10] davey@php.net Automatic comment on behalf of laruence@gmail.com Revision: http://git.php.net/?p=php-src.git;a=commit;h=9aa73d38000b9bb9de8dc8aa96e7dcef30506202 Log: Fixed bug #71729 (Possible crash in zend_bin_strtod, zend_oct_strtod, zend_hex_strtod) ------------------------------------------------------------------------ [2016-03-09 04:17:01] laruence@php.net Automatic comment on behalf of laruence@gmail.com Revision: http://git.php.net/?p=php-src.git;a=commit;h=9aa73d38000b9bb9de8dc8aa96e7dcef30506202 Log: Fixed bug #71729 (Possible crash in zend_bin_strtod, zend_oct_strtod, zend_hex_strtod) ------------------------------------------------------------------------ [2016-03-07 11:12:15] dragondreamer at live dot com Description: ------------ These three function has a flaw that can eventually result in crash: ZEND_API double zend_bin_strtod(const char *str, const char **endptr) { ... if (strlen(str) < 2) { *endptr = str; <--- No check if endptr is NULL, can result in zero pointer dereferencing return 0.0; } ... if (NULL != endptr) { <--- But here this check is present *endptr = (char *)(any ? s - 1 : str); } return value; } ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=71729&edit=1

« previous php.bugs (#218095) next »