Bug #67619 [NEW]: Length parameters in socket_write() etc. may be negative

From: Date: Mon, 14 Jul 2014 22:54:28 +0000
Subject: Bug #67619 [NEW]: Length parameters in socket_write() etc. may be negative
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-186615@lists.php.net to get a copy of this message
From:             tstarling
Operating system: Linux
PHP version:      5.6Git-2014-07-14 (Git)
Package:          Sockets related
Bug Type:         Bug
Bug description:Length parameters in socket_write() etc. may be negative

Description:
------------
In socket_write(), socket_send() and socket_sendto(), it is not checked
whether the length parameter is negative. If it is negative, it will be
converted to a size_t for the underlying syscall, so a write of more
than 2GB will be requested. In my testing, this fails with EFAULT. It is
conceivable that it may instead be a buffer overflow on some embedded
systems.

I suggest validating the length parameter.

Test script:
---------------
$f = socket_create(AF_INET, SOCK_STREAM,  SOL_TCP);
socket_connect($f, '127.0.0.1',8888);
socket_write($f, "Hello\n", -1);


Actual result:
--------------
Warning: socket_write(): unable to write to socket [14]: Bad address


-- 
Edit bug report at https://bugs.php.net/bug.php?id=67619&edit=1
-- 



Thread (3 messages)

« previous php.bugs (#186615) next »