Sec Bug->Bug #73119 [Opn]: Wrong return with addEmptyDir Zip Method

From: Date: Wed, 21 Sep 2016 02:28:55 +0000
Subject: Sec Bug->Bug #73119 [Opn]: Wrong return with addEmptyDir Zip Method
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-204160@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73119&edit=1 ID: 73119 Updated by: stas@php.net Reported by: hoangtuan180991 at gmail dot com Summary: Wrong return with addEmptyDir Zip Method Status: Open -Type: Security +Type: Bug Package: Filesystem function related Operating System: Ubuntu 12.04 PHP Version: 7.1.0RC2 Block user comment: N Private report: Y Previous Comments: ------------------------------------------------------------------------ [2016-09-20 05:58:30] hoangtuan180991 at gmail dot com Description: ------------ function static ZIPARCHIVE_METHOD(addEmptyDir) still return true but the directory did not created. idx = zip_stat(intern, s, 0, &sb); if (idx >= 0) { RETVAL_FALSE; } else { if (zip_add_dir(intern, (const char *)s) == -1) { RETVAL_FALSE; } zip_error_clear(intern); RETVAL_TRUE; } I propose the following patch: ````` --- a/ext/zip/php_zip.c +++ b/ext/zip/php_zip.c @@ -1603,10 +1603,14 @@ static ZIPARCHIVE_METHOD(addEmptyDir) RETVAL_FALSE; } else { if (zip_add_dir(intern, (const char *)s) == -1) { + zip_error_clear(intern); RETVAL_FALSE; } - zip_error_clear(intern); - RETVAL_TRUE; + else + { + zip_error_clear(intern); + RETVAL_TRUE; + } } if (s != dirname) { Test script: --------------- <?php ini_set('memory_limit', -1); $archive = new ZipArchive(); $archive->open('_test.zip', ZIPARCHIVE::CREATE); var_dump($archive->addEmptyDir(str_repeat("t", 0x7fffffff))); print_r($archive); $archive->close(); ?> Expected result: ---------------- bool(false) ZipArchive Object ( [status] => 0 [statusSys] => 0 [numFiles] => 0 [filename] => /home/tuannh/BUGS/TBB_TEST/_test.zip [comment] => ) Actual result: -------------- bool(true) ZipArchive Object ( [status] => 0 [statusSys] => 0 [numFiles] => 0 [filename] => /home/tuannh/BUGS/TBB_TEST/_test.zip [comment] => ) ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=73119&edit=1

« previous php.bugs (#204160) next »