#42222 [Opn->Csd]: php_openssl_make_REQ() buffer overflow
ID: 42222
Updated by: pajoye@php.net
Reported By: zatanzlatan at hotbrev dot com
-Status: Open
+Status: Closed
Bug Type: OpenSSL related
Operating System: Linux
PHP Version: 5CVS-2007-08-06 (CVS)
-Assigned To:
+Assigned To: pajoye
New Comment:
Thanks for the detailed report!
Fixed in 5.2 and HEAD.
Previous Comments:
------------------------------------------------------------------------
[2007-08-06 18:10:52] zatanzlatan at hotbrev dot com
Description:
------------
function php_openssl_make_REQ() in ext/openssl/openssl.c has buffer
overflow when parsing openssl.conf
look at this:
char buffer[200];
v = sk_CONF_VALUE_value(dn_sk, i);
type = v->name;
len = strlen(type);
if (len < sizeof("_default")) {
continue;
}
len -= sizeof("_default") - 1;
if (strcmp("_default", type + len) != 0) {
continue;
}
memcpy(buffer, type, len);
buffer[len] = '\0';
no check if name field with "_default" removed is larger than 200!
if u change "0.organizationName_default" in openssl.conf to "0." + 300
chars + "_default" then the buffer will be overflown in the memcpy().
Reproduce code:
---------------
u can test this with openssl_csr_new().
Expected result:
----------------
program should keep running.
Actual result:
--------------
program crashed.
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=42222&edit=1
Thread (2 messages)