Sec Bug->Bug #73122 [Opn]: Integer Overflow when concatenating strings
| From: | stas@php.net | Date: | Tue, 20 Sep 2016 16:26:22 +0000 |
| Subject: | Sec Bug->Bug #73122 [Opn]: Integer Overflow when concatenating strings | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-204155@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=73122&edit=1
ID: 73122
Updated by: stas@php.net
Reported by: tloi at fortinet dot com
Summary: Integer Overflow when concatenating strings
Status: Open
-Type: Security
+Type: Bug
Package: Strings related
PHP Version: master-Git-2016-09-20 (Git)
Block user comment: N
Private report: Y
Previous Comments:
------------------------------------------------------------------------
[2016-09-20 10:06:34] tloi at fortinet dot com
Description:
------------
Recently I notice php has been patched several times to prevent generating negative-length string to
mitigate security issue. But the concat operation can still be used to overflow the length of
string.
PoC ran on 32 bit version
This can be patched by checking len in either:
ZEND_CONCAT_*() functions in Zend_vm_execute.h
or
zend_string_extend() function in Zend_string.h
Test script:
---------------
<?php
ini_set('memory_limit', -1);
$a = str_repeat('a',0x7fffffff)."aa";
print strlen($a);
?>
Expected result:
----------------
zend_throw_error(NULL, "String size overflow");
Actual result:
--------------
â bin ./php -v
PHP 7.2.0-dev (cli) (built: Sep 20 2016 16:41:04) ( NTS DEBUG )
Copyright (c) 1997-2016 The PHP Group
Zend Engine v3.1.0-dev, Copyright (c) 1998-2016 Zend Technologies
â bin ./php poc.php
-2147483647#
===================
on another machine with php from ubuntu's official repository:
root@ubuntu-4gb-sgp1-01:~# php -v
PHP 7.0.8-0ubuntu0.16.04.2 (cli) ( NTS )
Copyright (c) 1997-2016 The PHP Group
Zend Engine v3.0.0, Copyright (c) 1998-2016 Zend Technologies
with Zend OPcache v7.0.8-0ubuntu0.16.04.2, Copyright (c) 1999-2016, by Zend Technologies
root@ubuntu-4gb-sgp1-01:~# php poc.php
mmap() failed: [12] Cannot allocate memory
[1] 16589 segmentation fault (core dumped) php poc.php
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=73122&edit=1