Req #73809 [Opn]: Phar Zip parse crash - mmap fail
| From: | eyal dot itkin at gmail dot com | Date: | Sat, 31 Dec 2016 09:21:52 +0000 |
| Subject: | Req #73809 [Opn]: Phar Zip parse crash - mmap fail | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-206260@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=73809&edit=1
ID: 73809
User updated by: eyal dot itkin at gmail dot com
Reported by: eyal dot itkin at gmail dot com
Summary: Phar Zip parse crash - mmap fail
Status: Open
Type: Feature/Change Request
Package: PHAR related
PHP Version: 7.1.0
Block user comment: N
Private report: N
New Comment:
I don't think I agree.
The fix is to return an error (via regular expression) instead of crashing the PHP process with
trace of:
mmap() failed: [22] invalid argument
...
PHP Fatal error.
The module lacks size checks that causes it to crash, this is not a feature request.
Previous Comments:
------------------------------------------------------------------------
[2016-12-31 09:16:42] stas@php.net
OK, if this is about changing fatal error to more friendly error handling, it's not a security
issue.
------------------------------------------------------------------------
[2016-12-31 09:07:15] eyal dot itkin at gmail dot com
There are several options to limit the ZIP's size in the PHAR module. In all of the cases we
want to trade a FATAL exception (i.e. a crash) with a normal exception error that indicates the ZIP
is too large.
Some background:
1) TAR archive in the PHAR module can't be bigger than 512 bytes.
2) PHAR archive is limited to 100MB.
3) The ZIP archive in the PHAR module has an overall limit of 64KB.
The only thing that is not limited is the size of the signature.bin inside the ZIP archive.
In addition, this signature is supposed to hold a supported signature:
1) MD5 - 16 bytes
2) SHA1 - 20 bytes
3) SHA256 - 32 bytes
4) SHA512 - 64 bytes
5) OPENSSL - not exactly clear to me how many bytes the SSL library is expecting
I think it is safe to limit the uncompressed signature size to 64KB:
1) Cryptographic signatures can not be compressed efficiently. Meaning that the size of a compressed
valid signature will almost be as large as the original uncompressed signature
2) The overall size for the ZIP archive is 64KB
3) As for today OPENSSL does not support any signature of size > 10KB.
------------------------------------------------------------------------
[2016-12-31 00:10:02] stas@php.net
I'm not sure I understand this one - what you mean by "extensive allocations"? Which
number would be considered "extensive"? Of course it is possible that the file is too big
for PHP to process - this is a legitimate error condition, not a security issue. Could you explain
the security issue you see here?
------------------------------------------------------------------------
[2016-12-27 08:47:28] eyal dot itkin at gmail dot com
Added the example_hostile.phar at this link: http://www.cs.tau.ac.il/~eyalitki/Upload/73809/
Added also the python script that generated it.
------------------------------------------------------------------------
[2016-12-27 07:05:01] stas@php.net
Please provide example_hostile.phar
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=73809
--
Edit this bug report at https://bugs.php.net/bug.php?id=73809&edit=1