Sec Bug->Bug #67252 [Opn->Csd]: convert_uudecode out-of-bounds read

From: Date: Wed, 14 May 2014 00:16:42 +0000
Subject: Sec Bug->Bug #67252 [Opn->Csd]: convert_uudecode out-of-bounds read
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-185813@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=67252&edit=1 ID: 67252 Updated by: stas@php.net Reported by: stas@php.net Summary: convert_uudecode out-of-bounds read -Status: Open +Status: Closed -Type: Security +Type: Bug Package: *General Issues Operating System: * PHP Version: 5.4.28 -Assigned To: +Assigned To: stas Block user comment: N Private report: Y New Comment: The fix for this bug has been committed. Snapshots of the sources are packaged every three hours; this change will be in the next snapshot. You can grab the snapshot at http://snaps.php.net/. For Windows: http://windows.php.net/snapshots/ Thank you for the report, and for helping us make PHP better. Previous Comments: ------------------------------------------------------------------------ [2014-05-12 03:30:27] stas@php.net The following patch has been added/updated: Patch Name: fix-uudecode Revision: 1399865427 URL: https://bugs.php.net/patch-display.php?bug=67252&patch=fix-uudecode&revision=1399865427 ------------------------------------------------------------------------ [2014-05-12 03:23:30] stas@php.net oops, script was cut off. Repro script is: $a = "M86%A86%A86%A86%A86%A86%A86%A86%A86%A86%A86%A86%A86%A86%A86%A"."\n"."!."; var_dump(convert_uudecode($a)); ------------------------------------------------------------------------ [2014-05-12 03:22:39] stas@php.net Description: ------------ convert_uudecode does not check the string length and thus tries to read past string end on short strings. Test script: --------------- $a = "M86%A86%A86%A86%A86%A86%A86%A86%A86%A86%A86%A86%A86%A86%A86%A"."\n"."!."; Expected result: ---------------- no memory errors Actual result: -------------- ==4264== Invalid read of size 1 ==4264== at 0x7B9FCA: php_uudecode (uuencode.c:156) ==4264== by 0x7BA0FB: zif_convert_uudecode (uuencode.c:216) ==4264== by 0x8FA502: zend_do_fcall_common_helper_SPEC (zend_vm_execute.h:550) ==4264== by 0x8EBD9F: execute_ex (zend_vm_execute.h:363) ==4264== by 0x877B28: zend_execute_scripts (zend.c:1316) ==4264== by 0x819828: php_execute_script (main.c:2506) ==4264== by 0x92863B: do_cli (php_cli.c:994) ==4264== by 0x928DD7: main (php_cli.c:1378) ==4264== Address 0x15ffb671 is 0 bytes after a block of size 65 alloc'd ==4264== at 0x4C26FDE: malloc (vg_replace_malloc.c:236) ==4264== by 0x870014: concat_function (zend_operators.c:1329) ==4264== by 0x8D835F: ZEND_CONCAT_SPEC_TMP_CONST_HANDLER (zend_vm_execute.h:8510) ==4264== by 0x8EBD9F: execute_ex (zend_vm_execute.h:363) ==4264== by 0x877B28: zend_execute_scripts (zend.c:1316) ==4264== by 0x819828: php_execute_script (main.c:2506) ==4264== by 0x92863B: do_cli (php_cli.c:994) ==4264== by 0x928DD7: main (php_cli.c:1378) ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=67252&edit=1

« previous php.bugs (#185813) next »