Bug #81691 [PATCH]: use-after-free of spl file handle

From: Date: Sat, 21 Jan 2023 23:19:16 +0000
Subject: Bug #81691 [PATCH]: use-after-free of spl file handle
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-243520@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81691&edit=1 ID: 81691 Patch added by: sample@email.tst Reported by: cuirongzhen at huawei dot com Summary: use-after-free of spl file handle Status: Open Type: Bug Package: SPL related Operating System: openEuler/Ubuntu 20.04.1 PHP Version: 8.1.0 Block user comment: N Private report: N New Comment: The following patch has been added/updated: Patch Name: pHqghUme Revision: 1674343156 URL: https://bugs.php.net/patch-display.php?bug=81691&patch=pHqghUme&revision=1674343156 Previous Comments: ------------------------------------------------------------------------ [2022-12-26 11:46:49] asri dot jase0352 at gmail dot com Thanks for sharing such great information, the post you published have some great information which is quite beneficial for me. I highly appreciated with your work abilities. (https://www.officefootballpool.net/)github.com ------------------------------------------------------------------------ [2022-12-23 08:28:43] marlynrasavong at gmail dot com There are more modes, but these are the most commonly used. After you have a FILE pointer, you can use basically the same IO commands. (https://www.dunkinuniversity.org/)github.com ------------------------------------------------------------------------ [2022-12-08 07:10:05] Puckett3265elena at gmail dot com (https://www.mymorri.net/)github.com To calculate pages you have to count PAGE headers. Here is a part of code which does it SpoolFilename = Path.ChangeExtension(SpoolFilename, ".SPL") '\\ Open a binary reader for the spool file Dim SpoolFileStream As New System.IO.FileStream(SpoolFilename, FileMode.Open, FileAccess.Read) Dim SpoolBinaryReader As New BinaryReader(SpoolFileStream, System.Text.Encoding.UTF8) 'Read the spooler records and count the total pages Dim recNext As EMFMetaRecordHeader = NextHeader(SpoolBinaryReader) While recNext.iType <> SpoolerRecordTypes.SRT_EOF If recNext.iType = SpoolerRecordTypes.SRT_PAGE Then _Pages += 1 End If 'SpoolfileReaderPerformaceCounter.Increment() Call SkipAHeader(recNext, SpoolBinaryReader) recNext = NextHeader(SpoolBinaryReader) End While ------------------------------------------------------------------------ [2022-01-12 20:09:11] camporter1 at gmail dot com The following pull request has been associated: Patch Name: [SPL] Prevent fclose on underlying SplFileObject file stream. On GitHub: https://github.com/php/php-src/pull/7920 Patch: https://github.com/php/php-src/pull/7920.patch ------------------------------------------------------------------------ [2021-12-03 10:52:09] cmb@php.net Thanks for reporting this issue! I don't think this qualifies as security issue, but it is certainly bad that the underlying resource can be accessed directly without the knowledge of the object, which causes all kinds of issues (e.g. changing the stream position on the resource would not cause a segfault, but other erroneous behavior). ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=81691 -- Edit this bug report at https://bugs.php.net/bug.php?id=81691&edit=1

« previous php.bugs (#243520) next »