Sec Bug->Bug #68955 [Opn->Nab]: Int overflow in ext/bz2/bz2.c

From: Date: Sun, 01 Feb 2015 07:06:03 +0000
Subject: Sec Bug->Bug #68955 [Opn->Nab]: Int overflow in ext/bz2/bz2.c
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-190381@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68955&edit=1 ID: 68955 Updated by: stas@php.net Reported by: bugreports at internot dot info -Summary: Int overflow +Summary: Int overflow in ext/bz2/bz2.c -Status: Open +Status: Not a bug -Type: Security +Type: Bug Package: Bzip2 Related Operating System: Linux Ubuntu 14.04 PHP Version: master-Git-2015-01-30 (Git) Block user comment: N Private report: Y New Comment: Thank you for taking the time to write to us, but this is not a bug. Please double-check the documentation available at http://www.php.net/manual/ and the instructions on how to report a bug at http://bugs.php.net/how-to-report.php total_out_hi32 already is unsigned int: unsigned int total_out_hi32; Previous Comments: ------------------------------------------------------------------------ [2015-01-30 03:14:57] bugreports at internot dot info Description: ------------ Hi, In /ext/bz2/bz2.c: 597 size = (bzs.total_out_hi32 * (unsigned int) -1) + bzs.total_out_lo32; and 603 size = (bzs.total_out_hi32 * (unsigned int) -1) + bzs.total_out_lo32; bzs.total_out_hi32 should be cast to unsigned int, to avoid an int overflow. (is that -1 even right? that'll be a huge number since it's unsigned) ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=68955&edit=1

« previous php.bugs (#190381) next »