Re: Re: com php-src: Partial fix for bug #68365 (zend_mm_heap corrupted after memory overflow in zend_hash_copy): Zend/zend_variables.c
| From: | Andrea Faulds | Date: | Fri, 07 Nov 2014 18:21:40 +0000 |
| Subject: | Re: Re: com php-src: Partial fix for bug #68365 (zend_mm_heap corrupted after memory overflow in zend_hash_copy): Zend/zend_variables.c | ||
| References: | 1 2 3 4 5 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-78850@lists.php.net to get a copy of this message | ||
> On 7 Nov 2014, at 18:11, Rasmus Lerdorf <rasmus@lerdorf.com> wrote:
>
> On 11/07/2014 06:52 AM, Ferenc Kovacs wrote:
>> 5.4 is in security fix mode, let see what Stas thinks about this.
>
> I am not that concerned about 5.4. People should be upgrading. But we
> should get this into the next 5.5 and 5.6 releases.
Since it corrupts the heap, perhaps it could be considered a security thing? I mean, that thing
*might* be exploitable.
--
Andrea Faulds
http://ajf.me/