Bug #70480 [Fbk->Csd]: php_url_parse_ex() buffer overflow read

From: Date: Mon, 28 Sep 2015 20:09:06 +0000
Subject: Bug #70480 [Fbk->Csd]: php_url_parse_ex() buffer overflow read
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-196286@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70480&edit=1

 ID:                 70480
 Updated by:         stas@php.net
 Reported by:        yohgaki@php.net
 Summary:            php_url_parse_ex() buffer overflow read
-Status:             Feedback
+Status:             Closed
 Type:               Bug
 Package:            URL related
 Operating System:   Irrelevant
 PHP Version:        Irrelevant
 Assigned To:        yohgaki
 Block user comment: N
 Private report:     N

 New Comment:

Automatic comment on behalf of stas
Revision: http://git.php.net/?p=php-src.git;a=commit;h=629e4da7cc8b174acdeab84969cbfc606a019b31
Log: Fix bug #70480 (php_url_parse_ex() buffer overflow read)


Previous Comments:
------------------------------------------------------------------------
[2015-09-28 09:17:22] yohgaki@php.net

For example, when smart_str is used, a code may assume php_url_prase_ex() operates up to
"length". The smart_str may not have terminating null char because it could be work in
progress string.

However, strchr() looks for terminating null char, but smart_str may not have terminating null char.
If this is the case, buffer overread happens and PHP crashes.

Anyway, php_url_prase_ex() is supposed to be binary safe as it has "length" parameter, but
it isn't due to the strchr().

------------------------------------------------------------------------
[2015-09-26 08:06:23] stas@php.net

Could you add an example when the buffer overflow/segfault happens?

------------------------------------------------------------------------
[2015-09-13 06:34:15] yohgaki@php.net

Description:
------------
php_url_prase_ex() read buffer exceeding its limits and segfaults.
PHP function parse_url() is not affected since PHP string is terminated by null char always.

Patch to fix this:

@@ -319,8 +320,9 @@ PHPAPI php_url *php_url_parse_ex(char const *str, size_t length)
 
        nohost:
 
        if ((p = memchr(s, '?', (ue - s)))) {
-               pp = strchr(s, '#');
+               pp = memchr(s, '#', (ue - s));
 
                if (pp && pp < p) {
                        if (pp - s) {


Test script:
---------------
N/A
This bug only appears only when php_url_prase_ex() is called internally.



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=70480&edit=1


Thread (4 messages)

« previous php.bugs (#196286) next »