Bug #67241 [Opn->Csd]: AddressSanitizer: global-buffer-overflow in phar_build
| From: | felipe@php.net | Date: | Sun, 11 May 2014 12:46:40 +0000 |
| Subject: | Bug #67241 [Opn->Csd]: AddressSanitizer: global-buffer-overflow in phar_build | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-185760@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=67241&edit=1
ID: 67241
Updated by: felipe@php.net
Reported by: crrodriguez at opensuse dot org
Summary: AddressSanitizer: global-buffer-overflow in
phar_build
-Status: Open
+Status: Closed
Type: Bug
Package: PHAR related
Operating System: linux
PHP Version: master-Git-2014-05-09 (Git)
-Assigned To:
+Assigned To: felipe
Block user comment: N
Private report: N
New Comment:
The fix for this bug has been committed.
Snapshots of the sources are packaged every three hours; this change
will be in the next snapshot. You can grab the snapshot at
http://snaps.php.net/.
For Windows:
http://windows.php.net/snapshots/
Thank you for the report, and for helping us make PHP better.
Previous Comments:
------------------------------------------------------------------------
[2014-05-09 22:10:30] crrodriguez at opensuse dot org
Description:
------------
There is an off-by-one in phar_build, misuse of estrndup
Test script:
---------------
running the phar test suite with -fsanitize=address + gcc 4.9
Expected result:
----------------
No error
Actual result:
--------------
==90012==ERROR: AddressSanitizer: global-buffer-overflow on address 0x0000011699c9 at pc 0xad1269 bp
0x7ffffd831c70 sp 0x7ffffd831c68
READ of size 1 at 0x0000011699c9 thread T0
#0 0xad1268 in memcpy /usr/include/bits/string3.h:51
#1 0xad1268 in _estrndup /home/crrodriguez/scm/php-src/Zend/zend_alloc.c:2655
#2 0x80682e in phar_build /home/crrodriguez/scm/php-src/ext/phar/phar_object.c:1480
#3 0x89ce86 in spl_iterator_apply /home/crrodriguez/scm/php-src/ext/spl/spl_iterators.c:3454
#4 0x801dba in zim_Phar_buildFromIterator
/home/crrodriguez/scm/php-src/ext/phar/phar_object.c:1919
#5 0xd8bf2e in zend_do_fcall_common_helper_SPEC
/home/crrodriguez/scm/php-src/Zend/zend_vm_execute.h:558
#6 0xc07060 in execute_ex /home/crrodriguez/scm/php-src/Zend/zend_vm_execute.h:363
#7 0xb4c26b in zend_execute_scripts /home/crrodriguez/scm/php-src/Zend/zend.c:1330
#8 0xa3b8c3 in php_execute_script /home/crrodriguez/scm/php-src/main/main.c:2549
#9 0xd901d1 in do_cli /home/crrodriguez/scm/php-src/sapi/cli/php_cli.c:994
#10 0x4387c2 in main /home/crrodriguez/scm/php-src/sapi/cli/php_cli.c:1378
#11 0x7f123098eb04 in __libc_start_main (/lib64/libc.so.6+0x21b04)
#12 0x438f86 (/home/crrodriguez/scm/php-src/sapi/cli/php+0x438f86)
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=67241&edit=1