Sec Bug->Bug #65744 [Opn->Fbk]: zend mm integer overflow

From: Date: Mon, 09 Jun 2014 05:45:00 +0000
Subject: Sec Bug->Bug #65744 [Opn->Fbk]: zend mm integer overflow
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-186110@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=65744&edit=1 ID: 65744 Updated by: stas@php.net Reported by: moltesalt at gmail dot com Summary: zend mm integer overflow -Status: Open +Status: Feedback -Type: Security +Type: Bug Package: Reproducible crash PHP Version: master-Git-2013-09-23 (Git) Block user comment: N Private report: Y New Comment: Thank you for this bug report. To properly diagnose the problem, we need a short but complete example script to be able to reproduce this bug ourselves. A proper reproducing script starts with <?php and ends with ?>, is max. 10-20 lines long and does not require any external resources such as databases, etc. If the script requires a database to demonstrate the issue, please make sure it creates all necessary tables, stored procedures etc. Please avoid embedding huge scripts into the report. Could you please provide some code example that reproduces the crash? Previous Comments: ------------------------------------------------------------------------ [2013-09-23 20:08:14] moltesalt at gmail dot com Description: ------------ The _estrndup() function requires length parameter as an unsigned int, but there are some macro and code block which pass a signed int. For example: http://lxr.php.net/xref/PHP_5_5/Zend/zend_API.h#582 http://lxr.php.net/xref/PHP_5_4/Zend/zend_API.h#578 578#define ZVAL_STRINGL(z, s, l, duplicate) do { \ 579 const char *__s=(s); int __l=l; \ 580 zval *__z = (z); \ 581 Z_STRLEN_P(__z) = __l; \ 582 Z_STRVAL_P(__z) = (duplicate?estrndup(__s, __l):(char*)__s);\ 583 Z_TYPE_P(__z) = IS_STRING; \ 584 } while (0) The successful exploit requires the control of both the string and length. Successful exploitation can lead to memory leak exploits. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=65744&edit=1

« previous php.bugs (#186110) next »