Bug #70480 [Asn->Fbk]: php_url_parse_ex() buffer overflow read

From: Date: Sat, 26 Sep 2015 08:06:23 +0000
Subject: Bug #70480 [Asn->Fbk]: php_url_parse_ex() buffer overflow read
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-196255@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70480&edit=1 ID: 70480 Updated by: stas@php.net Reported by: yohgaki@php.net Summary: php_url_parse_ex() buffer overflow read -Status: Assigned +Status: Feedback Type: Bug Package: URL related Operating System: Irrelevant PHP Version: Irrelevant Assigned To: yohgaki Block user comment: N Private report: N New Comment: Could you add an example when the buffer overflow/segfault happens? Previous Comments: ------------------------------------------------------------------------ [2015-09-13 06:34:15] yohgaki@php.net Description: ------------ php_url_prase_ex() read buffer exceeding its limits and segfaults. PHP function parse_url() is not affected since PHP string is terminated by null char always. Patch to fix this: @@ -319,8 +320,9 @@ PHPAPI php_url *php_url_parse_ex(char const *str, size_t length) nohost: if ((p = memchr(s, '?', (ue - s)))) { - pp = strchr(s, '#'); + pp = memchr(s, '#', (ue - s)); if (pp && pp < p) { if (pp - s) { Test script: --------------- N/A This bug only appears only when php_url_prase_ex() is called internally. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=70480&edit=1

« previous php.bugs (#196255) next »