Bug #73177 [Opn->Nab]: String size overflow in "addcslashes"
| From: | yohgaki@php.net | Date: | Tue, 27 Sep 2016 10:41:38 +0000 |
| Subject: | Bug #73177 [Opn->Nab]: String size overflow in "addcslashes" | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-204293@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=73177&edit=1
ID: 73177
Updated by: yohgaki@php.net
Reported by: david dot kurz at majorsecurity dot com
Summary: String size overflow in "addcslashes"
-Status: Open
+Status: Not a bug
Type: Bug
Package: *General Issues
Operating System: -Ubuntu SMP Fri Feb 19 14:27:58
PHP Version: 5.6.26
Block user comment: N
Private report: N
New Comment:
Reporter confirmed.
Previous Comments:
------------------------------------------------------------------------
[2016-09-26 21:43:35] david dot kurz at majorsecurity dot com
Hi again.
I originally found this in PHP 5.5.9 and there it had the overflow.
But after re-investigation the finding for PHP 5.5.26 today it seems to be a false-positive.
It now raises "zend_throw_error(NULL, "String size overflow");" which i believe
is fine.
Sorry for any confusion.
------------------------------------------------------------------------
[2016-09-26 12:29:45] david dot kurz at majorsecurity dot com
Description:
------------
There seems to be a String size overflow in "addcslashes()".
Test script:
---------------
============================
ENVIRONMENT:
============================
./sapi/cli/php -v
PHP 5.6.26 (cli) (built: Sep 26 2016 13:46:50)
Copyright (c) 1997-2016 The PHP Group
Zend Engine v2.6.0, Copyright (c) 1998-2016 Zend Technologies
============================
Proof of Concept PHP Code:
============================
<?php
ini_set('memory_limit', -1);
$str = str_repeat("'", 0xffffffff/4+1);
$overflow = addcslashes($str, "'");
var_dump(strlen($overflow));
?>
============================
============================
Output:
============================
Fatal error: String size overflow in
/data/home/secalert/Desktop/afl-2.34b/php-5.6.26/_overflows/addcslashes_01.php
============================
GDB:
============================
sec@alert:~/Desktop/afl-2.34b/php-5.6.26$ gdb -q -iex "set auto-load safe-path /"
./sapi/cli/php
Reading symbols from ./sapi/cli/php...done.
(gdb) run /data/home/secalert/Desktop/afl-2.34b/php-5.6.26/_overflows/addcslashes_01.php
Starting program: /data/home/secalert/Desktop/afl-2.34b/php-5.6.26/_overflows/addcslashes_01.php
[Thread debugging using libthread_db enabled]
Using host libthread_db library "/lib/x86_64-linux-gnu/libthread_db.so.1".
Fatal error: String size overflow in
/data/home/secalert/Desktop/afl-2.34b/php-5.6.26/_overflows/addcslashes_01.php on line 5
[Inferior 1 (process 21576) exited with code 0377]
(gdb) bt
Expected result:
----------------
There should be an exception handler and none overflow.
Actual result:
--------------
There seems to be a String size overflow in "addcslashes()".
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=73177&edit=1