Sec Bug->Bug #67250 [Csd]: iptcparse out-of-bounds read
| From: | stas@php.net | Date: | Wed, 14 May 2014 00:18:15 +0000 |
| Subject: | Sec Bug->Bug #67250 [Csd]: iptcparse out-of-bounds read | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-185816@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=67250&edit=1
ID: 67250
Updated by: stas@php.net
Reported by: stas@php.net
Summary: iptcparse out-of-bounds read
Status: Closed
-Type: Security
+Type: Bug
Package: *General Issues
Operating System: *
PHP Version: 5.4.28
Assigned To: stas
Block user comment: N
Private report: N
Previous Comments:
------------------------------------------------------------------------
[2014-05-14 00:16:09] stas@php.net
The fix for this bug has been committed.
Snapshots of the sources are packaged every three hours; this change
will be in the next snapshot. You can grab the snapshot at
http://snaps.php.net/.
For Windows:
http://windows.php.net/snapshots/
Thank you for the report, and for helping us make PHP better.
------------------------------------------------------------------------
[2014-05-12 02:10:25] stas@php.net
The following patch has been added/updated:
Patch Name: fix-iptcparse
Revision: 1399860625
URL: https://bugs.php.net/patch-display.php?bug=67250&patch=fix-iptcparse&revision=1399860625
------------------------------------------------------------------------
[2014-05-12 01:51:37] stas@php.net
Description:
------------
The code in iptcparse has insufficient bounds checking and can read past the end of the string.
Test script:
---------------
iptcparse("\x1C\x02_\x80___");
Expected result:
----------------
no memory errors
Actual result:
--------------
==18573== Conditional jump or move depends on uninitialised value(s)
==18573== at 0x787A2F: zif_iptcparse (iptc.c:340)
==18573== by 0x8FA5E2: zend_do_fcall_common_helper_SPEC (zend_vm_execute.h:550)
==18573== by 0x8EBE7F: execute_ex (zend_vm_execute.h:363)
==18573== by 0x86A089: zend_eval_stringl (zend_execute_API.c:1187)
==18573== by 0x86A168: zend_eval_stringl_ex (zend_execute_API.c:1234)
==18573== by 0x928472: do_cli (php_cli.c:1034)
==18573== by 0x928EB7: main (php_cli.c:1378)
==18573==
==18573== Conditional jump or move depends on uninitialised value(s)
==18573== at 0x787A33: zif_iptcparse (iptc.c:340)
==18573== by 0x8FA5E2: zend_do_fcall_common_helper_SPEC (zend_vm_execute.h:550)
==18573== by 0x8EBE7F: execute_ex (zend_vm_execute.h:363)
==18573== by 0x86A089: zend_eval_stringl (zend_execute_API.c:1187)
==18573== by 0x86A168: zend_eval_stringl_ex (zend_execute_API.c:1234)
==18573== by 0x928472: do_cli (php_cli.c:1034)
==18573== by 0x928EB7: main (php_cli.c:1378)
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=67250&edit=1