com php-src: Partial fix for bug #68365 (zend_mm_heap c orrupted after memory overflow in zend_hash_copy ): Zend/zend_variables.c
| From: | Dmitry Stogov | Date: | Fri, 07 Nov 2014 06:46:49 +0000 |
| Subject: | com php-src: Partial fix for bug #68365 (zend_mm_heap c orrupted after memory overflow in zend_hash_copy ): Zend/zend_variables.c | ||
| Groups: | php.cvs | ||
| Request: | Send a blank email to php-cvs+get-82966@lists.php.net to get a copy of this message | ||
Commit: 9dfa843a386b65b18353c510f032e322004d0bb7
Author: Dmitry Stogov <dmitry@zend.com> Fri, 7 Nov 2014 09:46:49 +0300
Parents: 0ddcf2a919a24cccb36bd0a69b05e6bbfc0bf883
Branches: PHP-5.4 PHP-5.5 PHP-5.6 master
Link: http://git.php.net/?p=php-src.git;a=commitdiff;h=9dfa843a386b65b18353c510f032e322004d0bb7
Log:
Partial fix for bug #68365 (zend_mm_heap corrupted after memory overflow in zend_hash_copy)
Bugs:
https://bugs.php.net/68365
Changed paths:
M Zend/zend_variables.c
Diff:
diff --git a/Zend/zend_variables.c b/Zend/zend_variables.c
index 9674de5..cc73c37 100644
--- a/Zend/zend_variables.c
+++ b/Zend/zend_variables.c
@@ -135,9 +135,9 @@ ZEND_API void _zval_copy_ctor_func(zval *zvalue ZEND_FILE_LINE_DC)
}
ALLOC_HASHTABLE_REL(tmp_ht);
zend_hash_init(tmp_ht, zend_hash_num_elements(original_ht), NULL, ZVAL_PTR_DTOR, 0);
+ zvalue->value.ht = tmp_ht;
zend_hash_copy(tmp_ht, original_ht, (copy_ctor_func_t) zval_add_ref, (void *) &tmp,
sizeof(zval *));
tmp_ht->nNextFreeElement = original_ht->nNextFreeElement;
- zvalue->value.ht = tmp_ht;
}
break;
case IS_OBJECT: