#42862 [Asn]: [PATCH] IMAP toolkit crash: rfc822.c legacy routine buffer overflow

From: Date: Tue, 14 Oct 2008 18:48:06 +0000
Subject: #42862 [Asn]: [PATCH] IMAP toolkit crash: rfc822.c legacy routine buffer overflow
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-129693@lists.php.net to get a copy of this message
ID: 42862 Updated by: stas@php.net Reported By: Maylein at ub dot uni-heidelberg dot de Status: Assigned Bug Type: IMAP related Operating System: * PHP Version: 5.2.6 Assigned To: pajoye New Comment: Also, what is the requirement for using rfc822_output_address_list - what is minimal c-client lib version that has it supported? Previous Comments: ------------------------------------------------------------------------ [2008-10-14 00:38:06] stas@php.net Looking at the current code, it looks like there's no actual overflow, but rfc822_write_address is limited so the abort happens. I am not seeing code path that would lead to rfc822_write_address writing more data than buffer size, unless I misunderstand how _php_imap_address_size works. Is this impression correct? If so, we still need to fix it since abort() is a nasty things, but it doesn't seem to be a security issue. ------------------------------------------------------------------------ [2008-07-21 21:48:00] pajoye@php.net I will give it some love while working on the imap lib. ------------------------------------------------------------------------ [2008-07-08 18:27:11] david at blue-labs dot org please fix 008_imap-bufferoverflows.patch to include the typedef for RFC822BUFFER. /* Output buffering for RFC [2]822 */ typedef long (*soutr_t) (void *stream,char *string); typedef struct rfc822buffer { soutr_t f; /* I/O flush routine */ void *s; /* stream for I/O routine */ char *beg; /* start of buffer */ char *cur; /* current buffer pointer */ char *end; /* end of buffer */ } RFC822BUFFER; ------------------------------------------------------------------------ [2008-06-24 10:54:50] hoffie at gentoo dot org This is CVE-2008-2829. ------------------------------------------------------------------------ [2008-06-18 17:43:50] hoffie at gentoo dot org Over 7 months and two releases have passed, yet no developer even commented on this *security* issue (according to the c-client devs). So what's up with this, are there any problems with the patch? If yes, would you mind pointing them out, so that one can try to fix them? ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at http://bugs.php.net/42862 -- Edit this bug report at http://bugs.php.net/?id=42862&edit=1

« previous php.bugs (#129693) next »