Bug #68690 [Com]: Off-by-one out-of-bounds write
| From: | bugreports at internot dot info | Date: | Tue, 30 Dec 2014 04:09:02 +0000 |
| Subject: | Bug #68690 [Com]: Off-by-one out-of-bounds write | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-189325@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=68690&edit=1
ID: 68690
Comment by: bugreports at internot dot info
Reported by: bugreports at internot dot info
Summary: Off-by-one out-of-bounds write
Status: Open
Type: Bug
Package: mbstring related
Operating System: Linux Ubuntu 14.04
PHP Version: master-Git-2014-12-30 (Git)
Block user comment: N
Private report: N
New Comment:
There is also questionable code in /ext/mbstring/libmbfl/filters/mbfilter_big5.c:
262 for (k = 0; k < sizeof(cp950_pua_tbl)/(sizeof(unsigned short)*4); k++)
{
263 if (c <= cp950_pua_tbl[k][1]) {
264 break;
265 }
266 }
267 c1 = c - cp950_pua_tbl[k][0];
^^ 'k' may be up to '5', which overruns it, I believe.
Thanks,
Previous Comments:
------------------------------------------------------------------------
[2014-12-30 04:05:18] bugreports at internot dot info
Description:
------------
Hi,
In /ext/mbstring/libmbfl/filters/mbfilter_sjis_2004.c:
508 if ((filter->status & 0xf) == 1 &&
509 filter->cache >= 0 && filter->cache <= jisx0213_u2_tbl_len) {
This implies that filter->cache can be between (inclusive) 0-25.
Then:
514 c1 = jisx0213_u2_tbl[2*k];
If k is 25, it will evaluate to 50.
It also may occur here:
519 if (c == jisx0213_u2_tbl[2*k+1]) {
Thanks,
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=68690&edit=1