Bug #73177 [Com]: String size overflow in "addcslashes"

From: Date: Mon, 26 Sep 2016 21:43:36 +0000
Subject: Bug #73177 [Com]: String size overflow in "addcslashes"
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-204290@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73177&edit=1 ID: 73177 Comment by: david dot kurz at majorsecurity dot com Reported by: david dot kurz at majorsecurity dot com Summary: String size overflow in "addcslashes" Status: Open Type: Bug Package: *General Issues Operating System: -Ubuntu SMP Fri Feb 19 14:27:58 PHP Version: 5.6.26 Block user comment: N Private report: N New Comment: Hi again. I originally found this in PHP 5.5.9 and there it had the overflow. But after re-investigation the finding for PHP 5.5.26 today it seems to be a false-positive. It now raises "zend_throw_error(NULL, "String size overflow");" which i believe is fine. Sorry for any confusion. Previous Comments: ------------------------------------------------------------------------ [2016-09-26 12:29:45] david dot kurz at majorsecurity dot com Description: ------------ There seems to be a String size overflow in "addcslashes()". Test script: --------------- ============================ ENVIRONMENT: ============================ ./sapi/cli/php -v PHP 5.6.26 (cli) (built: Sep 26 2016 13:46:50) Copyright (c) 1997-2016 The PHP Group Zend Engine v2.6.0, Copyright (c) 1998-2016 Zend Technologies ============================ Proof of Concept PHP Code: ============================ <?php ini_set('memory_limit', -1); $str = str_repeat("'", 0xffffffff/4+1); $overflow = addcslashes($str, "'"); var_dump(strlen($overflow)); ?> ============================ ============================ Output: ============================ Fatal error: String size overflow in /data/home/secalert/Desktop/afl-2.34b/php-5.6.26/_overflows/addcslashes_01.php ============================ GDB: ============================ sec@alert:~/Desktop/afl-2.34b/php-5.6.26$ gdb -q -iex "set auto-load safe-path /" ./sapi/cli/php Reading symbols from ./sapi/cli/php...done. (gdb) run /data/home/secalert/Desktop/afl-2.34b/php-5.6.26/_overflows/addcslashes_01.php Starting program: /data/home/secalert/Desktop/afl-2.34b/php-5.6.26/_overflows/addcslashes_01.php [Thread debugging using libthread_db enabled] Using host libthread_db library "/lib/x86_64-linux-gnu/libthread_db.so.1". Fatal error: String size overflow in /data/home/secalert/Desktop/afl-2.34b/php-5.6.26/_overflows/addcslashes_01.php on line 5 [Inferior 1 (process 21576) exited with code 0377] (gdb) bt Expected result: ---------------- There should be an exception handler and none overflow. Actual result: -------------- There seems to be a String size overflow in "addcslashes()". ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=73177&edit=1

« previous php.bugs (#204290) next »