Bug #81190 [Com]: 2 crashes(heap-buffer-overflow,SEGV) 5 memory leaks

From: Date: Thu, 01 Jul 2021 14:59:18 +0000
Subject: Bug #81190 [Com]: 2 crashes(heap-buffer-overflow,SEGV) 5 memory leaks
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-234742@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81190&edit=1 ID: 81190 Comment by: gutaotao1995 at qq dot com Reported by: gutaotao1995 at qq dot com Summary: 2 crashes(heap-buffer-overflow,SEGV) 5 memory leaks Status: Open Type: Bug Package: *General Issues Operating System: linux PHP Version: 8.1.0alpha1 Block user comment: N Private report: N New Comment: Thanks for your answer. After your identification, are these issues of mine a security issue? Doesn't one belong ? Previous Comments: ------------------------------------------------------------------------ [2021-07-01 14:46:47] nikic@php.net crash-php-execute is fixed by https://github.com/php/php-src/commit/353f963bba4f9abcba7d4609e56d0cf2e8af8dfc. leak-570847a2eeae3e477d2ba8253adb1ca3f78feb26 is a tricky issue for which I don't have an immediate fix. Filed https://bugs.php.net/bug.php?id=81216 to track it for now, with some additional information. @gutaotao1995 at qq dot com: The reductions are just simplified versions of the original inputs. Regarding CVEs, the PHP project only classifies issues that are potentially remotely expoitable as security issues, see https://wiki.php.net/security for the policy. ------------------------------------------------------------------------ [2021-07-01 14:07:49] gutaotao1995 at qq dot com Thank you very much for your contribution to PHP . ------------------------------------------------------------------------ [2021-07-01 13:56:48] gutaotao1995 at qq dot com Thank you again for your work, your efficiency is so high! Can I assign a CVE number to the POC I reported? ------------------------------------------------------------------------ [2021-07-01 13:55:41] gutaotao1995 at qq dot com Thanks for your work! Hello, some leak vulnerabilities have been fixed, but they are indeed triggered on the latest build of oss-fuzz. Regarding other crashes, such as heap-UAF, have other leak vulnerabilities successfully reproduced? In your comment, what does the final "reduction" mean? Please explain to me, is it impossible to reproduce? Or has it been confirmed as a vulnerability? ------------------------------------------------------------------------ [2021-07-01 13:54:34] nikic@php.net leak-6b6a01c65b09e6170fa2c931a69bbd10b72dfa2d is fixed by https://github.com/php/php-src/commit/36f5d719f5ae005fe9ff47160a02cb57a189bc37. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=81190 -- Edit this bug report at https://bugs.php.net/bug.php?id=81190&edit=1

« previous php.bugs (#234742) next »