Sec Bug->Bug #66183 [Opn]: Converting large strings to floats

From: Date: Thu, 12 Dec 2013 05:29:59 +0000
Subject: Sec Bug->Bug #66183 [Opn]: Converting large strings to floats
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-183249@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=66183&edit=1 ID: 66183 Updated by: laruence@php.net Reported by: aatallah at stanford dot edu Summary: Converting large strings to floats Status: Open -Type: Security +Type: Bug Package: Strings related Operating System: Mac OS X 10.9 PHP Version: Irrelevant Block user comment: N Private report: Y CVE-ID: 2013-4164 New Comment: hmm, misunderstood, this is not a security bug for php Previous Comments: ------------------------------------------------------------------------ [2013-11-27 14:17:42] aatallah at stanford dot edu Description: ------------ I'm using PHP 5.4.17 (cli) (built: Aug 25 2013 02:03:38), the default shipped by Apple now. See the test script. When a string-representation of a decimal is large enough, converting it to a float causes "Fatal error: Balloc() allocation exceeds list boundary in php shell code on line 1" and terminates the script. This is similar to Ruby's bug, publicized at https://www.ruby-lang.org/en/news/2013/11/22/heap-overflow-in-floating-point-parsing-cve-2013-4164/. Ruby fixed this by avoiding the Bigint freelist in Balloc; perhaps PHP should do something better than having a hard cutoff for k in Balloc. Test script: --------------- echo floatval("1.".str_repeat("1", 300000)); Expected result: ---------------- 1.1111111111111, which is the output of echo floatval("1.".str_repeat("1", 300)); Actual result: -------------- Fatal error: Balloc() allocation exceeds list boundary in php shell code on line 1 ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=66183&edit=1

« previous php.bugs (#183249) next »