Bug #73177 [NEW]: String size overflow in "addcslashes"
| From: | david dot kurz at majorsecurity dot com | Date: | Mon, 26 Sep 2016 12:29:48 +0000 |
| Subject: | Bug #73177 [NEW]: String size overflow in "addcslashes" | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-204279@lists.php.net to get a copy of this message | ||
From: david dot kurz at majorsecurity dot com
Operating system: -Ubuntu SMP Fri Feb 19 14:27:58
PHP version: 5.6.26
Package: *General Issues
Bug Type: Bug
Bug description:String size overflow in "addcslashes"
Description:
------------
There seems to be a String size overflow in "addcslashes()".
Test script:
---------------
============================
ENVIRONMENT:
============================
./sapi/cli/php -v
PHP 5.6.26 (cli) (built: Sep 26 2016 13:46:50)
Copyright (c) 1997-2016 The PHP Group
Zend Engine v2.6.0, Copyright (c) 1998-2016 Zend Technologies
============================
Proof of Concept PHP Code:
============================
<?php
ini_set('memory_limit', -1);
$str = str_repeat("'", 0xffffffff/4+1);
$overflow = addcslashes($str, "'");
var_dump(strlen($overflow));
?>
============================
============================
Output:
============================
Fatal error: String size overflow in
/data/home/secalert/Desktop/afl-2.34b/php-5.6.26/_overflows/addcslashes_01.php
============================
GDB:
============================
sec@alert:~/Desktop/afl-2.34b/php-5.6.26$ gdb -q -iex "set auto-load
safe-path /" ./sapi/cli/php
Reading symbols from ./sapi/cli/php...done.
(gdb) run
/data/home/secalert/Desktop/afl-2.34b/php-5.6.26/_overflows/addcslashes_01.php
Starting program:
/data/home/secalert/Desktop/afl-2.34b/php-5.6.26/_overflows/addcslashes_01.php
[Thread debugging using libthread_db enabled]
Using host libthread_db library
"/lib/x86_64-linux-gnu/libthread_db.so.1".
Fatal error: String size overflow in
/data/home/secalert/Desktop/afl-2.34b/php-5.6.26/_overflows/addcslashes_01.php
on line 5
[Inferior 1 (process 21576) exited with code 0377]
(gdb) bt
Expected result:
----------------
There should be an exception handler and none overflow.
Actual result:
--------------
There seems to be a String size overflow in "addcslashes()".
--
Edit bug report at https://bugs.php.net/bug.php?id=73177&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=73177&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=73177&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=73177&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=73177&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=73177&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=73177&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=73177&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=73177&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=73177&r=support
Expected behavior: https://bugs.php.net/fix.php?id=73177&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=73177&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=73177&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=73177&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=73177&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=73177&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=73177&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=73177&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=73177&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=73177&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=73177&r=mysqlcfg