Sec Bug->Bug #67250 [Csd]: iptcparse out-of-bounds read

From: Date: Wed, 14 May 2014 00:18:15 +0000
Subject: Sec Bug->Bug #67250 [Csd]: iptcparse out-of-bounds read
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-185816@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=67250&edit=1 ID: 67250 Updated by: stas@php.net Reported by: stas@php.net Summary: iptcparse out-of-bounds read Status: Closed -Type: Security +Type: Bug Package: *General Issues Operating System: * PHP Version: 5.4.28 Assigned To: stas Block user comment: N Private report: N Previous Comments: ------------------------------------------------------------------------ [2014-05-14 00:16:09] stas@php.net The fix for this bug has been committed. Snapshots of the sources are packaged every three hours; this change will be in the next snapshot. You can grab the snapshot at http://snaps.php.net/. For Windows: http://windows.php.net/snapshots/ Thank you for the report, and for helping us make PHP better. ------------------------------------------------------------------------ [2014-05-12 02:10:25] stas@php.net The following patch has been added/updated: Patch Name: fix-iptcparse Revision: 1399860625 URL: https://bugs.php.net/patch-display.php?bug=67250&patch=fix-iptcparse&revision=1399860625 ------------------------------------------------------------------------ [2014-05-12 01:51:37] stas@php.net Description: ------------ The code in iptcparse has insufficient bounds checking and can read past the end of the string. Test script: --------------- iptcparse("\x1C\x02_\x80___"); Expected result: ---------------- no memory errors Actual result: -------------- ==18573== Conditional jump or move depends on uninitialised value(s) ==18573== at 0x787A2F: zif_iptcparse (iptc.c:340) ==18573== by 0x8FA5E2: zend_do_fcall_common_helper_SPEC (zend_vm_execute.h:550) ==18573== by 0x8EBE7F: execute_ex (zend_vm_execute.h:363) ==18573== by 0x86A089: zend_eval_stringl (zend_execute_API.c:1187) ==18573== by 0x86A168: zend_eval_stringl_ex (zend_execute_API.c:1234) ==18573== by 0x928472: do_cli (php_cli.c:1034) ==18573== by 0x928EB7: main (php_cli.c:1378) ==18573== ==18573== Conditional jump or move depends on uninitialised value(s) ==18573== at 0x787A33: zif_iptcparse (iptc.c:340) ==18573== by 0x8FA5E2: zend_do_fcall_common_helper_SPEC (zend_vm_execute.h:550) ==18573== by 0x8EBE7F: execute_ex (zend_vm_execute.h:363) ==18573== by 0x86A089: zend_eval_stringl (zend_execute_API.c:1187) ==18573== by 0x86A168: zend_eval_stringl_ex (zend_execute_API.c:1234) ==18573== by 0x928472: do_cli (php_cli.c:1034) ==18573== by 0x928EB7: main (php_cli.c:1378) ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=67250&edit=1

« previous php.bugs (#185816) next »