develooper Front page | perl.perl5.porters | Postings from August 2017

[perl #131866] Null Pointer Dereference in Perl_sv_setpv_bufsize

From:
Tony Cook via RT
Date:
August 21, 2017 05:24
Subject:
[perl #131866] Null Pointer Dereference in Perl_sv_setpv_bufsize
Message ID:
rt-4.0.24-23779-1503293055-1599.131866-15-0@perl.org
On Wed, 09 Aug 2017 17:52:11 -0700, tonyc wrote:
> This simplifies down to:
> 
> $_.=*_='x';
> 
> and is a stack-not-refcounted bug.
> 
> This isn't a security issue - it depends on the code executed
> destroying an SV as it's assigned to, which is only under the control
> of an attacker.

Now public and linked to the stack-not-refcounted meta ticket.

Tony



---
via perlbug:  queue: perl5 status: open
https://rt.perl.org/Ticket/Display.html?id=131866



nntp.perl.org: Perl Programming lists via nntp and http.
Comments to Ask Bjørn Hansen at ask@perl.org | Group listing | About