Bug #69511 [Opn->Fbk]: Off-by-one bufferoverflow in php_sys_readlink
| From: | ab@php.net | Date: | Thu, 23 Apr 2015 14:26:03 +0000 |
| Subject: | Bug #69511 [Opn->Fbk]: Off-by-one bufferoverflow in php_sys_readlink | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-192297@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=69511&edit=1
ID: 69511
Updated by: ab@php.net
Reported by: jan dot starke at t-systems dot com
Summary: Off-by-one bufferoverflow in php_sys_readlink
-Status: Open
+Status: Feedback
Type: Bug
Package: Filesystem function related
Operating System: Windows
PHP Version: master-Git-2015-04-23 (Git)
-Assigned To:
+Assigned To: ab
Block user comment: N
Private report: N
New Comment:
In the core this is not an issue, looking through the codes - any target in a buf[MAXPATHLEN] . Then
it's also checked with >=, so there's the room for \0. However yep, the
php_sys_readlink is an exported symbol, so when ignoring target_len and a user passed target_len
< MAXLENPATH, it'll overflow the target. So I'd rather not touch the places where
it's used, but make it respect the target_len and check also dwRet >= target_len || dwRet
>= MAXLENPATH ...
Thanks.
Previous Comments:
------------------------------------------------------------------------
[2015-04-23 09:57:53] jan dot starke at t-systems dot com
Description:
------------
php_sys_readlink ignores the target_len parameter (which equals MAXPATHLEN-1) and instead passes
MAXPATHLEN to GetFinalPathNameByHandle. Because GetFinalPathNameByHandle actually writes a
terminating null character, this could lead to a off-by-one buffer overflow.
However, php_sys_readlink should not assume the length of the target buffer, but should use
target_len instead.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=69511&edit=1