Bug #81190 [Com]: 2 crashes(heap-buffer-overflow,SEGV) 5 memory leaks

From: Date: Fri, 02 Jul 2021 08:36:33 +0000
Subject: Bug #81190 [Com]: 2 crashes(heap-buffer-overflow,SEGV) 5 memory leaks
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-234754@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81190&edit=1 ID: 81190 Comment by: gutaotao1995 at qq dot com Reported by: gutaotao1995 at qq dot com Summary: 2 crashes(heap-buffer-overflow,SEGV) 5 memory leaks Status: Closed Type: Bug Package: *General Issues Operating System: linux PHP Version: 8.1.0alpha1 Assigned To: nikic Block user comment: N Private report: N New Comment: Thanks a lot. Previous Comments: ------------------------------------------------------------------------ [2021-07-02 08:26:07] nikic@php.net Looks like crash-eb98564ea8b9e5328defbc17269cfc2c6874d304 is a duplicate of bug #80173, which is now fixed as well. With that all issues here are fixed, apart from bug #81216, which is tracked separately. @gutaotao1995 at qq dot com: I don't see any way to remote exploit any of these issues, because they require specific malicious code on the server side (rather than, say, specific inputs to otherwise harmless code). As such, we don't track these as security issues. ------------------------------------------------------------------------ [2021-07-01 14:59:18] gutaotao1995 at qq dot com Thanks for your answer. After your identification, are these issues of mine a security issue? Doesn't one belong ? ------------------------------------------------------------------------ [2021-07-01 14:46:47] nikic@php.net crash-php-execute is fixed by https://github.com/php/php-src/commit/353f963bba4f9abcba7d4609e56d0cf2e8af8dfc. leak-570847a2eeae3e477d2ba8253adb1ca3f78feb26 is a tricky issue for which I don't have an immediate fix. Filed https://bugs.php.net/bug.php?id=81216 to track it for now, with some additional information. @gutaotao1995 at qq dot com: The reductions are just simplified versions of the original inputs. Regarding CVEs, the PHP project only classifies issues that are potentially remotely expoitable as security issues, see https://wiki.php.net/security for the policy. ------------------------------------------------------------------------ [2021-07-01 14:07:49] gutaotao1995 at qq dot com Thank you very much for your contribution to PHP . ------------------------------------------------------------------------ [2021-07-01 13:56:48] gutaotao1995 at qq dot com Thank you again for your work, your efficiency is so high! Can I assign a CVE number to the POC I reported? ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=81190 -- Edit this bug report at https://bugs.php.net/bug.php?id=81190&edit=1

« previous php.bugs (#234754) next »