Sec Bug->Bug #72138 [Opn]: Integer Overflow in Length of String-typed ZVAL

From: Date: Tue, 10 May 2016 05:28:21 +0000
Subject: Sec Bug->Bug #72138 [Opn]: Integer Overflow in Length of String-typed ZVAL
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-200980@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72138&edit=1 ID: 72138 Updated by: stas@php.net Reported by: taoguangchen at icloud dot com Summary: Integer Overflow in Length of String-typed ZVAL Status: Open -Type: Security +Type: Bug -Package: *General Issues +Package: Reproducible crash Operating System: * -PHP Version: 5.5.35 +PHP Version: 5.6.21 Block user comment: N Private report: Y New Comment: This does not look like security issue - requires special code under unrealistic memory limit. Previous Comments: ------------------------------------------------------------------------ [2016-05-02 10:08:11] taoguangchen at icloud dot com Description: ------------ ``` typedef union _zvalue_value { long lval; /* long value */ double dval; /* double value */ struct { char *val; int len; } str; HashTable *ht; /* hash table value */ zend_object_value obj; } zvalue_value; ``` The len is defined as signed int, integer overflow is possible in some situations, that results in len into a negative value and get a corrupted string-typed ZVAL. ex: str_replace/str_ireplace ``` Z_STRLEN_P(result) = len + (char_count * (to_len - 1)); ``` PoC: ``` <?php ini_set('memory_limit', -1); $str = str_replace('B', 'AAAAAAAA', str_repeat('B', 0xffffffff/8)); var_dump(strlen($str)); ?> ``` ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=72138&edit=1

« previous php.bugs (#200980) next »