Req #73809 [Opn]: Phar Zip parse crash - mmap fail

From: Date: Sat, 31 Dec 2016 09:21:52 +0000
Subject: Req #73809 [Opn]: Phar Zip parse crash - mmap fail
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-206260@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73809&edit=1 ID: 73809 User updated by: eyal dot itkin at gmail dot com Reported by: eyal dot itkin at gmail dot com Summary: Phar Zip parse crash - mmap fail Status: Open Type: Feature/Change Request Package: PHAR related PHP Version: 7.1.0 Block user comment: N Private report: N New Comment: I don't think I agree. The fix is to return an error (via regular expression) instead of crashing the PHP process with trace of: mmap() failed: [22] invalid argument ... PHP Fatal error. The module lacks size checks that causes it to crash, this is not a feature request. Previous Comments: ------------------------------------------------------------------------ [2016-12-31 09:16:42] stas@php.net OK, if this is about changing fatal error to more friendly error handling, it's not a security issue. ------------------------------------------------------------------------ [2016-12-31 09:07:15] eyal dot itkin at gmail dot com There are several options to limit the ZIP's size in the PHAR module. In all of the cases we want to trade a FATAL exception (i.e. a crash) with a normal exception error that indicates the ZIP is too large. Some background: 1) TAR archive in the PHAR module can't be bigger than 512 bytes. 2) PHAR archive is limited to 100MB. 3) The ZIP archive in the PHAR module has an overall limit of 64KB. The only thing that is not limited is the size of the signature.bin inside the ZIP archive. In addition, this signature is supposed to hold a supported signature: 1) MD5 - 16 bytes 2) SHA1 - 20 bytes 3) SHA256 - 32 bytes 4) SHA512 - 64 bytes 5) OPENSSL - not exactly clear to me how many bytes the SSL library is expecting I think it is safe to limit the uncompressed signature size to 64KB: 1) Cryptographic signatures can not be compressed efficiently. Meaning that the size of a compressed valid signature will almost be as large as the original uncompressed signature 2) The overall size for the ZIP archive is 64KB 3) As for today OPENSSL does not support any signature of size > 10KB. ------------------------------------------------------------------------ [2016-12-31 00:10:02] stas@php.net I'm not sure I understand this one - what you mean by "extensive allocations"? Which number would be considered "extensive"? Of course it is possible that the file is too big for PHP to process - this is a legitimate error condition, not a security issue. Could you explain the security issue you see here? ------------------------------------------------------------------------ [2016-12-27 08:47:28] eyal dot itkin at gmail dot com Added the example_hostile.phar at this link: http://www.cs.tau.ac.il/~eyalitki/Upload/73809/ Added also the python script that generated it. ------------------------------------------------------------------------ [2016-12-27 07:05:01] stas@php.net Please provide example_hostile.phar ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=73809 -- Edit this bug report at https://bugs.php.net/bug.php?id=73809&edit=1

« previous php.bugs (#206260) next »