com php-src: Fixed use after free: ext/intl/breakiterator/ruleb asedbreakiterator_methods.cpp ext/intl/calendar/gregorian calendar_methods.cpp
ext/intl/collator/collator_create .c ext/intl/dateformat/dateformat_create.cpp ext/intl /formatter/formatter_main.c ext/intl/msgformat/msgformat .c
ext/intl/resourcebundle/resourcebundle_class.c

From: Date: Mon, 26 Jan 2015 09:24:33 +0000
Subject: com php-src: Fixed use after free: ext/intl/breakiterator/ruleb asedbreakiterator_methods.cpp ext/intl/calendar/gregorian calendar_methods.cpp
ext/intl/collator/collator_create .c ext/intl/dateformat/dateformat_create.cpp ext/intl /formatter/formatter_main.c ext/intl/msgformat/msgformat .c
ext/intl/resourcebundle/resourcebundle_class.c
Groups: php.cvs 
Request: Send a blank email to php-cvs+get-84366@lists.php.net to get a copy of this message
Commit: 8aa146b810108bde3353d9d2f8cf05a9dd012f6d Author: Dmitry Stogov <dmitry@zend.com> Mon, 26 Jan 2015 12:24:33 +0300 Parents: 371dc9b6a659399ede7d3c784f3c6ff800045ab2 Branches: master Link: http://git.php.net/?p=php-src.git;a=commitdiff;h=8aa146b810108bde3353d9d2f8cf05a9dd012f6d Log: Fixed use after free Changed paths: M ext/intl/breakiterator/rulebasedbreakiterator_methods.cpp M ext/intl/calendar/gregoriancalendar_methods.cpp M ext/intl/collator/collator_create.c M ext/intl/dateformat/dateformat_create.cpp M ext/intl/formatter/formatter_main.c M ext/intl/msgformat/msgformat.c M ext/intl/resourcebundle/resourcebundle_class.c Diff: diff --git a/ext/intl/breakiterator/rulebasedbreakiterator_methods.cpp b/ext/intl/breakiterator/rulebasedbreakiterator_methods.cpp index e359bac..c112134 100644 --- a/ext/intl/breakiterator/rulebasedbreakiterator_methods.cpp +++ b/ext/intl/breakiterator/rulebasedbreakiterator_methods.cpp @@ -104,7 +104,6 @@ U_CFUNC PHP_METHOD(IntlRuleBasedBreakIterator, __construct) if (Z_TYPE_P(return_value) == IS_OBJECT && Z_OBJ_P(return_value) == NULL) { zend_object_store_ctor_failed(Z_OBJ(orig_this)); - zval_dtor(&orig_this); ZEND_CTOR_MAKE_NULL(); } } diff --git a/ext/intl/calendar/gregoriancalendar_methods.cpp b/ext/intl/calendar/gregoriancalendar_methods.cpp index 2cb46e4..2ae5737 100644 --- a/ext/intl/calendar/gregoriancalendar_methods.cpp +++ b/ext/intl/calendar/gregoriancalendar_methods.cpp @@ -198,7 +198,6 @@ U_CFUNC PHP_METHOD(IntlGregorianCalendar, __construct) if (Z_TYPE_P(return_value) == IS_OBJECT && Z_OBJ_P(return_value) == NULL) { zend_object_store_ctor_failed(Z_OBJ(orig_this)); - zval_dtor(&orig_this); ZEND_CTOR_MAKE_NULL(); } } diff --git a/ext/intl/collator/collator_create.c b/ext/intl/collator/collator_create.c index dd81ebe..b205842 100644 --- a/ext/intl/collator/collator_create.c +++ b/ext/intl/collator/collator_create.c @@ -79,7 +79,6 @@ PHP_METHOD( Collator, __construct ) if (Z_TYPE_P(return_value) == IS_OBJECT && Z_OBJ_P(return_value) == NULL) { zend_object_store_ctor_failed(Z_OBJ(orig_this)); - zval_dtor(&orig_this); ZEND_CTOR_MAKE_NULL(); } } diff --git a/ext/intl/dateformat/dateformat_create.cpp b/ext/intl/dateformat/dateformat_create.cpp index 2ceee46..f8cf776 100644 --- a/ext/intl/dateformat/dateformat_create.cpp +++ b/ext/intl/dateformat/dateformat_create.cpp @@ -196,7 +196,6 @@ U_CFUNC PHP_METHOD( IntlDateFormatter, __construct ) if (Z_TYPE_P(return_value) == IS_OBJECT && Z_OBJ_P(return_value) == NULL) { zend_object_store_ctor_failed(Z_OBJ(orig_this)); - zval_dtor(&orig_this); ZEND_CTOR_MAKE_NULL(); } } diff --git a/ext/intl/formatter/formatter_main.c b/ext/intl/formatter/formatter_main.c index 59629a6..60db673 100644 --- a/ext/intl/formatter/formatter_main.c +++ b/ext/intl/formatter/formatter_main.c @@ -97,7 +97,6 @@ PHP_METHOD( NumberFormatter, __construct ) if (Z_TYPE_P(return_value) == IS_OBJECT && Z_OBJ_P(return_value) == NULL) { zend_object_store_ctor_failed(Z_OBJ(orig_this)); - zval_dtor(&orig_this); ZEND_CTOR_MAKE_NULL(); } } diff --git a/ext/intl/msgformat/msgformat.c b/ext/intl/msgformat/msgformat.c index bda8b57..707b38b 100644 --- a/ext/intl/msgformat/msgformat.c +++ b/ext/intl/msgformat/msgformat.c @@ -115,7 +115,6 @@ PHP_METHOD( MessageFormatter, __construct ) if (Z_TYPE_P(return_value) == IS_OBJECT && Z_OBJ_P(return_value) == NULL) { zend_object_store_ctor_failed(Z_OBJ(orig_this)); - zval_dtor(&orig_this); ZEND_CTOR_MAKE_NULL(); } } diff --git a/ext/intl/resourcebundle/resourcebundle_class.c b/ext/intl/resourcebundle/resourcebundle_class.c index 01823d7..9ce3373 100644 --- a/ext/intl/resourcebundle/resourcebundle_class.c +++ b/ext/intl/resourcebundle/resourcebundle_class.c @@ -146,7 +146,6 @@ PHP_METHOD( ResourceBundle, __construct ) if (Z_TYPE_P(return_value) == IS_OBJECT && Z_OBJ_P(return_value) == NULL) { zend_object_store_ctor_failed(Z_OBJ(orig_this)); - zval_dtor(&orig_this); ZEND_CTOR_MAKE_NULL(); } }

« previous php.cvs (#84366) next »