com php-src: Fixed use after free: ext/intl/breakiterator/ruleb asedbreakiterator_methods.cpp ext/intl/calendar/gregorian calendar_methods.cpp
ext/intl/collator/collator_create .c ext/intl/dateformat/dateformat_create.cpp ext/intl /formatter/formatter_main.c ext/intl/msgformat/msgformat .c
ext/intl/resourcebundle/resourcebundle_class.c
| From: | Dmitry Stogov | Date: | Mon, 26 Jan 2015 09:24:33 +0000 |
| Subject: | com php-src: Fixed use after free: ext/intl/breakiterator/ruleb asedbreakiterator_methods.cpp ext/intl/calendar/gregorian calendar_methods.cpp ext/intl/collator/collator_create .c ext/intl/dateformat/dateformat_create.cpp ext/intl /formatter/formatter_main.c ext/intl/msgformat/msgformat .c ext/intl/resourcebundle/resourcebundle_class.c |
||
| Groups: | php.cvs | ||
| Request: | Send a blank email to php-cvs+get-84366@lists.php.net to get a copy of this message | ||
Commit: 8aa146b810108bde3353d9d2f8cf05a9dd012f6d
Author: Dmitry Stogov <dmitry@zend.com> Mon, 26 Jan 2015 12:24:33 +0300
Parents: 371dc9b6a659399ede7d3c784f3c6ff800045ab2
Branches: master
Link: http://git.php.net/?p=php-src.git;a=commitdiff;h=8aa146b810108bde3353d9d2f8cf05a9dd012f6d
Log:
Fixed use after free
Changed paths:
M ext/intl/breakiterator/rulebasedbreakiterator_methods.cpp
M ext/intl/calendar/gregoriancalendar_methods.cpp
M ext/intl/collator/collator_create.c
M ext/intl/dateformat/dateformat_create.cpp
M ext/intl/formatter/formatter_main.c
M ext/intl/msgformat/msgformat.c
M ext/intl/resourcebundle/resourcebundle_class.c
Diff:
diff --git a/ext/intl/breakiterator/rulebasedbreakiterator_methods.cpp
b/ext/intl/breakiterator/rulebasedbreakiterator_methods.cpp
index e359bac..c112134 100644
--- a/ext/intl/breakiterator/rulebasedbreakiterator_methods.cpp
+++ b/ext/intl/breakiterator/rulebasedbreakiterator_methods.cpp
@@ -104,7 +104,6 @@ U_CFUNC PHP_METHOD(IntlRuleBasedBreakIterator, __construct)
if (Z_TYPE_P(return_value) == IS_OBJECT && Z_OBJ_P(return_value) == NULL) {
zend_object_store_ctor_failed(Z_OBJ(orig_this));
- zval_dtor(&orig_this);
ZEND_CTOR_MAKE_NULL();
}
}
diff --git a/ext/intl/calendar/gregoriancalendar_methods.cpp
b/ext/intl/calendar/gregoriancalendar_methods.cpp
index 2cb46e4..2ae5737 100644
--- a/ext/intl/calendar/gregoriancalendar_methods.cpp
+++ b/ext/intl/calendar/gregoriancalendar_methods.cpp
@@ -198,7 +198,6 @@ U_CFUNC PHP_METHOD(IntlGregorianCalendar, __construct)
if (Z_TYPE_P(return_value) == IS_OBJECT && Z_OBJ_P(return_value) == NULL) {
zend_object_store_ctor_failed(Z_OBJ(orig_this));
- zval_dtor(&orig_this);
ZEND_CTOR_MAKE_NULL();
}
}
diff --git a/ext/intl/collator/collator_create.c b/ext/intl/collator/collator_create.c
index dd81ebe..b205842 100644
--- a/ext/intl/collator/collator_create.c
+++ b/ext/intl/collator/collator_create.c
@@ -79,7 +79,6 @@ PHP_METHOD( Collator, __construct )
if (Z_TYPE_P(return_value) == IS_OBJECT && Z_OBJ_P(return_value) == NULL) {
zend_object_store_ctor_failed(Z_OBJ(orig_this));
- zval_dtor(&orig_this);
ZEND_CTOR_MAKE_NULL();
}
}
diff --git a/ext/intl/dateformat/dateformat_create.cpp b/ext/intl/dateformat/dateformat_create.cpp
index 2ceee46..f8cf776 100644
--- a/ext/intl/dateformat/dateformat_create.cpp
+++ b/ext/intl/dateformat/dateformat_create.cpp
@@ -196,7 +196,6 @@ U_CFUNC PHP_METHOD( IntlDateFormatter, __construct )
if (Z_TYPE_P(return_value) == IS_OBJECT && Z_OBJ_P(return_value) == NULL) {
zend_object_store_ctor_failed(Z_OBJ(orig_this));
- zval_dtor(&orig_this);
ZEND_CTOR_MAKE_NULL();
}
}
diff --git a/ext/intl/formatter/formatter_main.c b/ext/intl/formatter/formatter_main.c
index 59629a6..60db673 100644
--- a/ext/intl/formatter/formatter_main.c
+++ b/ext/intl/formatter/formatter_main.c
@@ -97,7 +97,6 @@ PHP_METHOD( NumberFormatter, __construct )
if (Z_TYPE_P(return_value) == IS_OBJECT && Z_OBJ_P(return_value) == NULL) {
zend_object_store_ctor_failed(Z_OBJ(orig_this));
- zval_dtor(&orig_this);
ZEND_CTOR_MAKE_NULL();
}
}
diff --git a/ext/intl/msgformat/msgformat.c b/ext/intl/msgformat/msgformat.c
index bda8b57..707b38b 100644
--- a/ext/intl/msgformat/msgformat.c
+++ b/ext/intl/msgformat/msgformat.c
@@ -115,7 +115,6 @@ PHP_METHOD( MessageFormatter, __construct )
if (Z_TYPE_P(return_value) == IS_OBJECT && Z_OBJ_P(return_value) == NULL) {
zend_object_store_ctor_failed(Z_OBJ(orig_this));
- zval_dtor(&orig_this);
ZEND_CTOR_MAKE_NULL();
}
}
diff --git a/ext/intl/resourcebundle/resourcebundle_class.c
b/ext/intl/resourcebundle/resourcebundle_class.c
index 01823d7..9ce3373 100644
--- a/ext/intl/resourcebundle/resourcebundle_class.c
+++ b/ext/intl/resourcebundle/resourcebundle_class.c
@@ -146,7 +146,6 @@ PHP_METHOD( ResourceBundle, __construct )
if (Z_TYPE_P(return_value) == IS_OBJECT && Z_OBJ_P(return_value) == NULL) {
zend_object_store_ctor_failed(Z_OBJ(orig_this));
- zval_dtor(&orig_this);
ZEND_CTOR_MAKE_NULL();
}
}