Memory corruption in internal get_icu_disp_value_src_php() function

Sec Bug #62082 Memory corruption in internal get_icu_disp_value_src_php() function
Submitted: 2012-05-20 20:15 UTC Modified: 2014-06-24 18:21 UTC
From: felipe@php.net Assigned: cataphract (profile)
Status: Closed Package: I18N and L10N related
PHP Version: Irrelevant OS: Linux
Private report: No CVE-ID: None

 [2012-05-20 20:15 UTC] felipe@php.net

Description:
------------
See below:

Test script:
---------------
<?php

locale_get_display_name(str_repeat("a", 300), $x);

Actual result:
--------------
[Sun May 20 17:12:36 2012]  Script:  '/home/felipe/dev/bug.php'
---------------------------------------
/home/felipe/dev/php5_3/ext/intl/locale/locale_methods.c(579) : Block 0x015b18a0 status:
Invalid pointer: ((size=0x00000261) != (next.prev=0x61006100610061))
---------------------------------------
Segmentation fault


Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports

 [2012-05-20 20:17 UTC] felipe@php.net

-Summary: Memory corruption in locale_get_display_name function +Summary: Memory corruption in internal get_icu_disp_value_src_php() function

 [2012-05-23 11:36 UTC] cataphract@php.net

-Status: Open +Status: Closed -Assigned To: +Assigned To: cataphract