com php-src: Partial fix for bug #68365 (zend_mm_heap c orrupted after memory overflow in zend_hash_copy ): Zend/zend_variables.c

From: Date: Fri, 07 Nov 2014 06:46:49 +0000
Subject: com php-src: Partial fix for bug #68365 (zend_mm_heap c orrupted after memory overflow in zend_hash_copy ): Zend/zend_variables.c
Groups: php.cvs 
Request: Send a blank email to php-cvs+get-82966@lists.php.net to get a copy of this message
Commit: 9dfa843a386b65b18353c510f032e322004d0bb7 Author: Dmitry Stogov <dmitry@zend.com> Fri, 7 Nov 2014 09:46:49 +0300 Parents: 0ddcf2a919a24cccb36bd0a69b05e6bbfc0bf883 Branches: PHP-5.4 PHP-5.5 PHP-5.6 master Link: http://git.php.net/?p=php-src.git;a=commitdiff;h=9dfa843a386b65b18353c510f032e322004d0bb7 Log: Partial fix for bug #68365 (zend_mm_heap corrupted after memory overflow in zend_hash_copy) Bugs: https://bugs.php.net/68365 Changed paths: M Zend/zend_variables.c Diff: diff --git a/Zend/zend_variables.c b/Zend/zend_variables.c index 9674de5..cc73c37 100644 --- a/Zend/zend_variables.c +++ b/Zend/zend_variables.c @@ -135,9 +135,9 @@ ZEND_API void _zval_copy_ctor_func(zval *zvalue ZEND_FILE_LINE_DC) } ALLOC_HASHTABLE_REL(tmp_ht); zend_hash_init(tmp_ht, zend_hash_num_elements(original_ht), NULL, ZVAL_PTR_DTOR, 0); + zvalue->value.ht = tmp_ht; zend_hash_copy(tmp_ht, original_ht, (copy_ctor_func_t) zval_add_ref, (void *) &tmp, sizeof(zval *)); tmp_ht->nNextFreeElement = original_ht->nNextFreeElement; - zvalue->value.ht = tmp_ht; } break; case IS_OBJECT:

« previous php.cvs (#82966) next »