Bug #76813 [Csd->ReO]: Access_violation_near_NULL_on_source_operand

From: Date: Tue, 15 Dec 2020 16:26:39 +0000
Subject: Bug #76813 [Csd->ReO]: Access_violation_near_NULL_on_source_operand
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-231099@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76813&edit=1 ID: 76813 Updated by: cmb@php.net Reported by: songmingxuan at cert dot org dot cn Summary: Access_violation_near_NULL_on_source_operand -Status: Closed +Status: Re-Opened Type: Bug Package: Reproducible crash Operating System: ubuntu/windows PHP Version: 7.2.9 Assigned To: cmb Block user comment: N Private report: N New Comment: The fix has been reverted from PHP-7.4 for now, because it is incompatible with re2c 0.13.5. Previous Comments: ------------------------------------------------------------------------ [2020-12-15 16:00:18] derick@php.net Automatic comment on behalf of github@derickrethans.nl Revision: http://git.php.net/?p=php-src.git;a=commit;h=a668ce82de2987502268a10c2b867b66d24d0708 Log: Revert &quot;Fix #76813: Access violation near NULL on source operand&quot; ------------------------------------------------------------------------ [2020-11-30 11:34:11] cmb@php.net Automatic comment on behalf of cmbecker69@gmx.de Revision: http://git.php.net/?p=php-src.git;a=commit;h=5e15c9c41f8318a8392c2e2c78544f218736549c Log: Fix #76813: Access violation near NULL on source operand ------------------------------------------------------------------------ [2020-11-27 15:05:17] cmb@php.net The following pull request has been associated: Patch Name: Fix #76813: Access_violation_near_NULL_on_source_operand On GitHub: https://github.com/php/php-src/pull/6464 Patch: https://github.com/php/php-src/pull/6464.patch ------------------------------------------------------------------------ [2018-09-06 15:02:33] songmingxuan at cert dot org dot cn This problem. It may be a Integer Overflow problem. It seems to affect phpdbg only. I suggest you repair it. ------------------------------------------------------------------------ [2018-09-06 14:42:23] cmb@php.net The problem is that the lexer doesn't properly recognize the end of the input, and calculates yyleng based on YYCURSOR[1], which may be zero. It seems to me that this also may result in a memory corruption, since entering the string on the prompt again, leads to a crash (tested on Windows). [1] <https://github.com/php/php-src/blob/php-7.3.0beta3/sapi/phpdbg/phpdbg_lexer.l#L87> ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=76813 -- Edit this bug report at https://bugs.php.net/bug.php?id=76813&edit=1

« previous php.bugs (#231099) next »