Bug #71750 [Opn->Csd]: Multiple Heap Overflows in php_raw_url_encode/php_url_encode

From: Date: Mon, 21 Mar 2016 06:11:10 +0000
Subject: Bug #71750 [Opn->Csd]: Multiple Heap Overflows in php_raw_url_encode/php_url_encode
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-199982@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71750&edit=1 ID: 71750 Updated by: stas@php.net Reported by: taoguangchen at icloud dot com Summary: Multiple Heap Overflows in php_raw_url_encode/php_url_encode -Status: Open +Status: Closed Type: Bug Package: *General Issues PHP Version: 7.0.4 Block user comment: N Private report: N New Comment: Automatic comment on behalf of stas Revision: http://git.php.net/?p=php-src.git;a=commit;h=c4517b2a5e3141393c1c4f6fca51e1c325e91251 Log: Fix bug #71750: use zend_string_safe_alloc for calculated allocations Previous Comments: ------------------------------------------------------------------------ [2016-03-21 05:38:47] stas@php.net This also does not look like security issue, requires specially crafted code. ------------------------------------------------------------------------ [2016-03-09 05:27:47] taoguangchen at icloud dot com Description: ------------ Vulnerable code: ``` PHPAPI zend_string *php_raw_url_encode(char const *s, size_t len) { ... str = zend_string_alloc(3 * len, 0); for (x = 0, y = 0; len--; x++, y++) { ZSTR_VAL(str)[y] = (unsigned char) s[x]; ... PHPAPI zend_string *php_url_encode(char const *s, size_t len) { ... start = zend_string_alloc(3 * len, 0); ``` PoC: ``` <?php //php_raw_url_encode ini_set('memory_limit', -1); rawurlencode(str_repeat('A', 0xffffffff/3)); ``` ``` <?php //php_url_encode ini_set('memory_limit', -1); setcookie('hi', str_repeat('A', 0xffffffff/3)); ``` Fix: uses zend_string_safe_alloc instead ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=71750&edit=1

« previous php.bugs (#199982) next »