Bug #69824 [NEW]: Core functions makes string overflow possible introducing strange behaviours
| From: | grzegorz129 at gmail dot com | Date: | Sat, 13 Jun 2015 23:21:42 +0000 |
| Subject: | Bug #69824 [NEW]: Core functions makes string overflow possible introducing strange behaviours | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-193435@lists.php.net to get a copy of this message | ||
From: grzegorz129 at gmail dot com
Operating system: OSX, Linux
PHP version: 5.6.10
Package: Strings related
Bug Type: Bug
Bug description:Core functions makes string overflow possible introducing strange behaviours
Description:
------------
Everyone is worried about producing a block hole in LHC, but no one is
watching evil PHP programmers at their homes. After years of hard work I
made it! Black hole is alive, it consumes everything... it even forced
strlen() to provide value below 0 ;)
Speaking serious when I saw documentation note about strings length
("Note: string can be as large as up to 2GB (2147483647 bytes maximum)")
I instantly started wondering if it's possible to break that limit and
what will happen after.
After some experiments I observed that some functions can create strings
bigger than 2147483647 bytes.
First script result looks funny but it's little boring. I started
digging more and created second one. After even more digging I noticed
memory allocation problem (3rd script) but what's the fun without
segfault?
Finally I created segfault using 4rd script. Unfortunately I'm unable to
provide backtrace since I don't have machine with newest PHP build with
debug enabled.
So yeah, string boundaries can be exploited and than PHP starts behaving
strangely ;)
Test script:
---------------
<?php
ini_set('memory_limit', '10G');
$size = (1024 * 1024 * 1024); //1 gigabyte
$test = str_repeat('a', $size);
$test2 = $test.$test;
//Result: PHP Fatal error: Allowed memory size of 10737418240 bytes
exhausted (tried to allocate 18446744071562067969 bytes)
------------------------------------
<?php
ini_set('memory_limit', '10G');
$size = (1024 * 1024 * 1024); //1 gigabyte
$test = str_repeat('a', $size);
$test2 = str_repeat($test, 2);
var_dump(strlen($test2)); //Result: -2
echo $test2; //Prints nothing
------------------------------------
<?php
ini_set('memory_limit', '10G');
$size = 2147483648;
$test = str_repeat('a', $size);
strlen( substr( str_repeat($test, 2), 1) );
------------------------------------
<?php
ini_set('memory_limit', '10G');
$size = 2147483648;
$test = str_repeat('a', $size);
$x[$test] = '';
var_dump($x);
--
Edit bug report at https://bugs.php.net/bug.php?id=69824&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=69824&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=69824&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=69824&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=69824&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=69824&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=69824&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=69824&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=69824&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=69824&r=support
Expected behavior: https://bugs.php.net/fix.php?id=69824&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=69824&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=69824&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=69824&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=69824&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=69824&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=69824&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=69824&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=69824&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=69824&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=69824&r=mysqlcfg