summaryrefslogtreecommitdiffstats
path: root/bug71391.patch
diff options
context:
space:
mode:
authorRemi Collet <fedora@famillecollet.com>2016-02-16 22:54:26 +0100
committerRemi Collet <fedora@famillecollet.com>2016-02-16 22:54:26 +0100
commit1ed943ec556f4bfa49a2700b30c9bb58a91379eb (patch)
treef1e7c3c5b9d1fa3e4fe78a0c80cde04a1e0333c5 /bug71391.patch
parent08069d1e5b43644dc9cac9bd4d645304320cc0d0 (diff)
php 5.4.45-4 (security fix backported from 5.5.32)
Diffstat (limited to 'bug71391.patch')
-rw-r--r--bug71391.patch31
1 files changed, 31 insertions, 0 deletions
diff --git a/bug71391.patch b/bug71391.patch
new file mode 100644
index 0000000..538953e
--- /dev/null
+++ b/bug71391.patch
@@ -0,0 +1,31 @@
+Backported from 5.5 for 5.4 by Remi Collet
+binary patch dropped
+
+From 1c1b8b69982375700d4b011eb89ea48b66dbd5aa Mon Sep 17 00:00:00 2001
+From: Stanislav Malyshev <stas@php.net>
+Date: Sat, 16 Jan 2016 20:43:43 -0800
+Subject: [PATCH] Fix bug #71391: NULL Pointer Dereference in
+ phar_tar_setupmetadata()
+
+---
+ ext/phar/tar.c | 3 +++
+ ext/phar/tests/bug71391.phpt | 18 ++++++++++++++++++
+ ext/phar/tests/bug71391.tar | Bin 0 -> 3584 bytes
+ 3 files changed, 21 insertions(+)
+ create mode 100644 ext/phar/tests/bug71391.phpt
+ create mode 100644 ext/phar/tests/bug71391.tar
+
+diff --git a/ext/phar/tar.c b/ext/phar/tar.c
+index 34ef0ef..5f26805 100644
+--- a/ext/phar/tar.c
++++ b/ext/phar/tar.c
+@@ -870,6 +870,9 @@ static int phar_tar_setupmetadata(void *pDest, void *argument TSRMLS_DC) /* {{{
+
+ if (entry->filename_len >= sizeof(".phar/.metadata") && !memcmp(entry->filename, ".phar/.metadata", sizeof(".phar/.metadata")-1)) {
+ if (entry->filename_len == sizeof(".phar/.metadata.bin")-1 && !memcmp(entry->filename, ".phar/.metadata.bin", sizeof(".phar/.metadata.bin")-1)) {
++ if (entry->phar->metadata == NULL) {
++ return ZEND_HASH_APPLY_REMOVE;
++ }
+ return phar_tar_setmetadata(entry->phar->metadata, entry, error TSRMLS_CC);
+ }
+ /* search for the file this metadata entry references */