Sec Bug->Bug #73082 [Csd]: string length overflow in mb_encode_* function
| From: | stas@php.net | Date: | Mon, 13 Feb 2017 01:19:46 +0000 |
| Subject: | Sec Bug->Bug #73082 [Csd]: string length overflow in mb_encode_* function | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-207332@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=73082&edit=1
ID: 73082
Updated by: stas@php.net
Reported by: secresearch at fortinet dot com
Summary: string length overflow in mb_encode_* function
Status: Closed
-Type: Security
+Type: Bug
Package: mbstring related
Operating System: ALL
PHP Version: 5.6.26RC1
Assigned To: stas
Block user comment: N
Private report: N
Previous Comments:
------------------------------------------------------------------------
[2016-10-17 10:07:48] bwoebi@php.net
Automatic comment on behalf of stas
Revision: http://git.php.net/?p=php-src.git;a=commit;h=e1709b7e588cbda71c577f6e5b701713d0c70a23
Log: Fix bug #73082
------------------------------------------------------------------------
[2016-10-14 02:23:15] ab@php.net
Automatic comment on behalf of stas
Revision: http://git.php.net/?p=php-src.git;a=commit;h=e1709b7e588cbda71c577f6e5b701713d0c70a23
Log: Fix bug #73082
------------------------------------------------------------------------
[2016-10-12 23:35:43] ab@php.net
Automatic comment on behalf of stas
Revision: http://git.php.net/?p=php-src.git;a=commit;h=e1709b7e588cbda71c577f6e5b701713d0c70a23
Log: Fix bug #73082
------------------------------------------------------------------------
[2016-10-11 23:45:52] stas@php.net
Automatic comment on behalf of stas
Revision: http://git.php.net/?p=php-src.git;a=commit;h=e1709b7e588cbda71c577f6e5b701713d0c70a23
Log: Fix bug #73082
------------------------------------------------------------------------
[2016-09-26 06:34:43] secresearch at fortinet dot com
The patch must looks like this:
--- PHP-5.6.26_old/ext/mbstring/libmbfl/mbfl/mbfilter.c 2016-09-26 11:54:21.369998637 +0800
+++ PHP-5.6.26/ext/mbstring/libmbfl/mbfl/mbfilter.c 2016-09-26 14:32:27.536978132 +0800
@@ -111,6 +111,7 @@
0x30,0x31,0x32,0x33,0x34,0x35,0x36,0x37,0x38,0x39,0x41,0x42,0x43,0x44,0x45,0x46
};
+#define INT_MAX_LIMIT ((1UL << (SIZEOF_INT * 8 - 1)) - 1)
/*
@@ -3042,7 +3043,7 @@
int n;
unsigned char *p;
- if (string == NULL || result == NULL) {
+ if (string == NULL || result == NULL || (string->len > INT_MAX_LIMIT/5)) {
return NULL;
}
mbfl_string_init(result);
output_len <= input_len*5 (5 times is the maximum output length, this depend on convmap, type of
encode. So I just leave 5 here for quick fix)
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=73082
--
Edit this bug report at https://bugs.php.net/bug.php?id=73082&edit=1