Re: Re: com php-src: Partial fix for bug #68365 (zend_mm_heap corrupted after memory overflow in zend_hash_copy): Zend/zend_variables.c

From: Date: Fri, 07 Nov 2014 18:21:40 +0000
Subject: Re: Re: com php-src: Partial fix for bug #68365 (zend_mm_heap corrupted after memory overflow in zend_hash_copy): Zend/zend_variables.c
References: 1 2 3 4 5  Groups: php.internals 
Request: Send a blank email to internals+get-78850@lists.php.net to get a copy of this message
> On 7 Nov 2014, at 18:11, Rasmus Lerdorf <rasmus@lerdorf.com> wrote: > > On 11/07/2014 06:52 AM, Ferenc Kovacs wrote: >> 5.4 is in security fix mode, let see what Stas thinks about this. > > I am not that concerned about 5.4. People should be upgrading. But we > should get this into the next 5.5 and 5.6 releases. Since it corrupts the heap, perhaps it could be considered a security thing? I mean, that thing *might* be exploitable. -- Andrea Faulds http://ajf.me/

« previous php.internals (#78850) next »