Bug #70480 [Asn->Fbk]: php_url_parse_ex() buffer overflow read
| From: | stas@php.net | Date: | Sat, 26 Sep 2015 08:06:23 +0000 |
| Subject: | Bug #70480 [Asn->Fbk]: php_url_parse_ex() buffer overflow read | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-196255@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=70480&edit=1
ID: 70480
Updated by: stas@php.net
Reported by: yohgaki@php.net
Summary: php_url_parse_ex() buffer overflow read
-Status: Assigned
+Status: Feedback
Type: Bug
Package: URL related
Operating System: Irrelevant
PHP Version: Irrelevant
Assigned To: yohgaki
Block user comment: N
Private report: N
New Comment:
Could you add an example when the buffer overflow/segfault happens?
Previous Comments:
------------------------------------------------------------------------
[2015-09-13 06:34:15] yohgaki@php.net
Description:
------------
php_url_prase_ex() read buffer exceeding its limits and segfaults.
PHP function parse_url() is not affected since PHP string is terminated by null char always.
Patch to fix this:
@@ -319,8 +320,9 @@ PHPAPI php_url *php_url_parse_ex(char const *str, size_t length)
nohost:
if ((p = memchr(s, '?', (ue - s)))) {
- pp = strchr(s, '#');
+ pp = memchr(s, '#', (ue - s));
if (pp && pp < p) {
if (pp - s) {
Test script:
---------------
N/A
This bug only appears only when php_url_prase_ex() is called internally.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=70480&edit=1