php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #68903 Use after free in Zend/zend_API.c
Submitted: 2015-01-24 19:08 UTC Modified: 2015-01-24 22:45 UTC
From: bugreports at internot dot info Assigned:
Status: Not a bug Package: *General Issues
PHP Version: 5.5.21 OS: Linux Ubuntu 14.04
Private report: No CVE-ID: None
 [2015-01-24 19:08 UTC] bugreports at internot dot info
Description:
------------
Hi,

In /Zend/zend_API.c:


3482                                property_info.name = (char*)name;

3493                        efree((char*)property_info.name);

but then:

3508        zend_hash_quick_update(&ce->properties_info, name, name_length+1, h, &property_info, sizeof(zend_property_info), NULL);
which does:

!memcmp(p->arKey, arKey, nKeyLength)

'arKey' = name.


Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2015-01-24 22:45 UTC] stas@php.net
-Summary: Use after free +Summary: Use after free in Zend/zend_API.c -Status: Open +Status: Not a bug -Type: Security +Type: Bug
 [2015-01-24 22:45 UTC] stas@php.net
The free happens only when interned_name != property_info.name, and this can not happen if IS_INTERNED(name) branch was taken earlier, since if name is interned, zend_new_interned_string_int() returns the same string - see code in zend_string.c.
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Thu Oct 08 09:00:02 2026 UTC