Sec Bug->Req #73809 [Opn]: Phar Zip parse crash - mmap fail
| From: | stas@php.net | Date: | Sat, 31 Dec 2016 09:16:42 +0000 |
| Subject: | Sec Bug->Req #73809 [Opn]: Phar Zip parse crash - mmap fail | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-206259@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=73809&edit=1
ID: 73809
Updated by: stas@php.net
Reported by: eyal dot itkin at gmail dot com
Summary: Phar Zip parse crash - mmap fail
Status: Open
-Type: Security
+Type: Feature/Change Request
Package: PHAR related
PHP Version: 7.1.0
Block user comment: N
Private report: Y
New Comment:
OK, if this is about changing fatal error to more friendly error handling, it's not a security
issue.
Previous Comments:
------------------------------------------------------------------------
[2016-12-31 09:07:15] eyal dot itkin at gmail dot com
There are several options to limit the ZIP's size in the PHAR module. In all of the cases we
want to trade a FATAL exception (i.e. a crash) with a normal exception error that indicates the ZIP
is too large.
Some background:
1) TAR archive in the PHAR module can't be bigger than 512 bytes.
2) PHAR archive is limited to 100MB.
3) The ZIP archive in the PHAR module has an overall limit of 64KB.
The only thing that is not limited is the size of the signature.bin inside the ZIP archive.
In addition, this signature is supposed to hold a supported signature:
1) MD5 - 16 bytes
2) SHA1 - 20 bytes
3) SHA256 - 32 bytes
4) SHA512 - 64 bytes
5) OPENSSL - not exactly clear to me how many bytes the SSL library is expecting
I think it is safe to limit the uncompressed signature size to 64KB:
1) Cryptographic signatures can not be compressed efficiently. Meaning that the size of a compressed
valid signature will almost be as large as the original uncompressed signature
2) The overall size for the ZIP archive is 64KB
3) As for today OPENSSL does not support any signature of size > 10KB.
------------------------------------------------------------------------
[2016-12-31 00:10:02] stas@php.net
I'm not sure I understand this one - what you mean by "extensive allocations"? Which
number would be considered "extensive"? Of course it is possible that the file is too big
for PHP to process - this is a legitimate error condition, not a security issue. Could you explain
the security issue you see here?
------------------------------------------------------------------------
[2016-12-27 08:47:28] eyal dot itkin at gmail dot com
Added the example_hostile.phar at this link: http://www.cs.tau.ac.il/~eyalitki/Upload/73809/
Added also the python script that generated it.
------------------------------------------------------------------------
[2016-12-27 07:05:01] stas@php.net
Please provide example_hostile.phar
------------------------------------------------------------------------
[2016-12-24 12:51:02] eyal dot itkin at gmail dot com
The bug is relevant only to the zip option in the phar module.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=73809
--
Edit this bug report at https://bugs.php.net/bug.php?id=73809&edit=1