#42222 [Opn->Csd]: php_openssl_make_REQ() buffer overflow

From: Date: Mon, 06 Aug 2007 19:13:43 +0000
Subject: #42222 [Opn->Csd]: php_openssl_make_REQ() buffer overflow
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-115810@lists.php.net to get a copy of this message
 ID:               42222
 Updated by:       pajoye@php.net
 Reported By:      zatanzlatan at hotbrev dot com
-Status:           Open
+Status:           Closed
 Bug Type:         OpenSSL related
 Operating System: Linux
 PHP Version:      5CVS-2007-08-06 (CVS)
-Assigned To:      
+Assigned To:      pajoye
 New Comment:

Thanks for the detailed report!

Fixed in 5.2 and HEAD.


Previous Comments:
------------------------------------------------------------------------

[2007-08-06 18:10:52] zatanzlatan at hotbrev dot com

Description:
------------
function php_openssl_make_REQ() in ext/openssl/openssl.c has buffer
overflow when parsing openssl.conf

look at this:

			char buffer[200];
			
			v = sk_CONF_VALUE_value(dn_sk, i);
			type = v->name;
			
			len = strlen(type);
			if (len < sizeof("_default")) {
				continue;
			}
			len -= sizeof("_default") - 1;
			if (strcmp("_default", type + len) != 0) {
				continue;
			}
			
			memcpy(buffer, type, len);
			buffer[len] = '\0';

no check if name field with "_default" removed is larger than 200!

if u change "0.organizationName_default" in openssl.conf to "0." + 300
chars + "_default" then the buffer will be overflown in the memcpy().

Reproduce code:
---------------
u can test this with openssl_csr_new().

Expected result:
----------------
program should keep running.

Actual result:
--------------
program crashed.


------------------------------------------------------------------------


-- 
Edit this bug report at http://bugs.php.net/?id=42222&edit=1


Thread (2 messages)

« previous php.bugs (#115810) next »