Bug #68690 [Com]: Off-by-one out-of-bounds write

From: Date: Tue, 30 Dec 2014 04:13:21 +0000
Subject: Bug #68690 [Com]: Off-by-one out-of-bounds write
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-189326@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68690&edit=1 ID: 68690 Comment by: bugreports at internot dot info Reported by: bugreports at internot dot info Summary: Off-by-one out-of-bounds write Status: Open Type: Bug Package: mbstring related Operating System: Linux Ubuntu 14.04 PHP Version: master-Git-2014-12-30 (Git) Block user comment: N Private report: N New Comment: Same code as above comment in the same file: L195-201. Thanks, Previous Comments: ------------------------------------------------------------------------ [2014-12-30 04:09:02] bugreports at internot dot info There is also questionable code in /ext/mbstring/libmbfl/filters/mbfilter_big5.c: 262 for (k = 0; k < sizeof(cp950_pua_tbl)/(sizeof(unsigned short)*4); k++) { 263 if (c <= cp950_pua_tbl[k][1]) { 264 break; 265 } 266 } 267 c1 = c - cp950_pua_tbl[k][0]; ^^ 'k' may be up to '5', which overruns it, I believe. Thanks, ------------------------------------------------------------------------ [2014-12-30 04:05:18] bugreports at internot dot info Description: ------------ Hi, In /ext/mbstring/libmbfl/filters/mbfilter_sjis_2004.c: 508 if ((filter->status & 0xf) == 1 && 509 filter->cache >= 0 && filter->cache <= jisx0213_u2_tbl_len) { This implies that filter->cache can be between (inclusive) 0-25. Then: 514 c1 = jisx0213_u2_tbl[2*k]; If k is 25, it will evaluate to 50. It also may occur here: 519 if (c == jisx0213_u2_tbl[2*k+1]) { Thanks, ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=68690&edit=1

« previous php.bugs (#189326) next »