Bug #77360 [Asn->Csd]: class_uses causes segfault
| From: | nikic@php.net | Date: | Thu, 27 Dec 2018 14:34:33 +0000 |
| Subject: | Bug #77360 [Asn->Csd]: class_uses causes segfault | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-218646@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77360&edit=1
ID: 77360
Updated by: nikic@php.net
Reported by: lauri dot kentta at gmail dot com
Summary: class_uses causes segfault
-Status: Assigned
+Status: Closed
Type: Bug
Package: SPL related
Operating System: Linux
PHP Version: 7.3.0
Assigned To: nikic
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of lauri.kentta@gmail.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=16c62a81795c253724a957d32e242545bb05253d
Log: Fix #77360: class_uses causes segfault
Previous Comments:
------------------------------------------------------------------------
[2018-12-27 14:15:47] lauri dot kentta at gmail dot com
Description:
------------
Similar to bug #77359, the function spl_find_ce_by_name has use-after-free of a zend_string and
causes segfault. This affects functions class_parents, class_implements and class_uses. This bug is
caused by commit 084c17fe0b68d391467fd48a14433443d4fcba81.
Test script:
---------------
<?php
$a = md5(""); # Create a non-interned string.
@class_uses($a, false); # Invalid free.
@class_uses($a, false); # Use after free.
echo "{$a} + foo\n"; # Use after free.
# Notice how "foo" is not printed even if the code does not crash.
# Run it a few times to get a crash.
?>
Expected result:
----------------
No crash and full output.
Actual result:
--------------
Crash or truncated output.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=77360&edit=1