Debian Bug report logs - #726037
php5: munmap() is called with the incorrect length

version graph

Package: php5; Maintainer for php5 is (unknown);

Reported by: William Dauchy <wdauchy@gmail.com>

Date: Fri, 11 Oct 2013 12:51:01 UTC

Severity: normal

Tags: patch

Found in version php5/5.4.4-14+deb7u5

Fixed in versions php5/5.4.4-14+deb7u7, 5.4.4-14+deb7u6

Done: Thijs Kinkhorst <thijs@debian.org>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, Debian PHP Maintainers <pkg-php-maint@lists.alioth.debian.org>:
Bug#726037; Package php5. (Fri, 11 Oct 2013 12:51:06 GMT) (full text, mbox, link).


Acknowledgement sent to William Dauchy <wdauchy@gmail.com>:
New Bug report received and forwarded. Copy sent to Debian PHP Maintainers <pkg-php-maint@lists.alioth.debian.org>. (Fri, 11 Oct 2013 12:51:06 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: William Dauchy <wdauchy@gmail.com>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: php5: munmap() is called with the incorrect length
Date: Fri, 11 Oct 2013 14:46:43 +0200
Package: php5
Version: 5.4.4-14+deb7u5
Severity: normal
Tags: patch

munmap() is called with the incorrect length resulting is possible
memoryleak.

A one year patch is present upstream
http://git.php.net/?p=php-src.git;a=commit;h=433089ccb4d4747a01d522e8678664ff17584615

Could be a good idea to fix the issue on wheezy version.

Regards,
-- 
William



Reply sent to Thijs Kinkhorst <thijs@debian.org>:
You have taken responsibility. (Thu, 12 Dec 2013 21:00:21 GMT) (full text, mbox, link).


Notification sent to William Dauchy <wdauchy@gmail.com>:
Bug acknowledged by developer. (Thu, 12 Dec 2013 21:00:22 GMT) (full text, mbox, link).


Message #10 received at 726037-done@bugs.debian.org (full text, mbox, reply):

From: Thijs Kinkhorst <thijs@debian.org>
To: 725868-done@bugs.debian.org, 725890-done@bugs.debian.org, 725972-done@bugs.debian.org, 726033-done@bugs.debian.org, 726037-done@bugs.debian.org, 726295-done@bugs.debian.org, 726320-done@bugs.debian.org, 726379-done@bugs.debian.org, 726627-done@bugs.debian.org, 726633-done@bugs.debian.org
Subject: fixed in php5 5.4.4-14+deb7u6
Date: Thu, 12 Dec 2013 21:57:49 +0100
[Message part 1 (text/plain, inline)]
Version: 5.4.4-14+deb7u6

php5 (5.4.4-14+deb7u6) stable; urgency=low

  [ William Dauchy ]
  * upstream fix: curl memory leak (Closes: #725868)
  * upstream fix: allow root to run php-fpm (Closes: #725890)
  * upstream fix: remove annoying warnings with php-fpm and user usage
    (Closes: #725972)
  * upstream fix: memoryleak in function declaration (Closes: #726033)
  * upstream fix: munmap() is called with the incorrect length (Closes: 
#726037)
  * upstream fix: segfault on zend_deactivate (Closes: #726295)
  * upstream fix: Possible null dereference (Closes: #726320)
  * upstream fix: Phar::buildFromDirectory creates corrupt archives
    (Closes: #726379)
  * upstream fix: segfault while loading extensions (Closes: #726627)
  * upstream fix: (un)serialize() leaves dangling pointers, causes crashes
    (Closes: #726633)
[signature.asc (application/pgp-signature, inline)]

Marked as fixed in versions php5/5.4.4-14+deb7u7. Request was from Ondřej Surý <ondrej@debian.org> to control@bugs.debian.org. (Thu, 12 Dec 2013 22:33:07 GMT) (full text, mbox, link).


Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Fri, 10 Jan 2014 07:29:53 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Sun Jul 2 03:12:38 2023; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.