Sec Bug->Bug #73082 [Csd]: string length overflow in mb_encode_* function

From: Date: Mon, 13 Feb 2017 01:19:46 +0000
Subject: Sec Bug->Bug #73082 [Csd]: string length overflow in mb_encode_* function
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-207332@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73082&edit=1 ID: 73082 Updated by: stas@php.net Reported by: secresearch at fortinet dot com Summary: string length overflow in mb_encode_* function Status: Closed -Type: Security +Type: Bug Package: mbstring related Operating System: ALL PHP Version: 5.6.26RC1 Assigned To: stas Block user comment: N Private report: N Previous Comments: ------------------------------------------------------------------------ [2016-10-17 10:07:48] bwoebi@php.net Automatic comment on behalf of stas Revision: http://git.php.net/?p=php-src.git;a=commit;h=e1709b7e588cbda71c577f6e5b701713d0c70a23 Log: Fix bug #73082 ------------------------------------------------------------------------ [2016-10-14 02:23:15] ab@php.net Automatic comment on behalf of stas Revision: http://git.php.net/?p=php-src.git;a=commit;h=e1709b7e588cbda71c577f6e5b701713d0c70a23 Log: Fix bug #73082 ------------------------------------------------------------------------ [2016-10-12 23:35:43] ab@php.net Automatic comment on behalf of stas Revision: http://git.php.net/?p=php-src.git;a=commit;h=e1709b7e588cbda71c577f6e5b701713d0c70a23 Log: Fix bug #73082 ------------------------------------------------------------------------ [2016-10-11 23:45:52] stas@php.net Automatic comment on behalf of stas Revision: http://git.php.net/?p=php-src.git;a=commit;h=e1709b7e588cbda71c577f6e5b701713d0c70a23 Log: Fix bug #73082 ------------------------------------------------------------------------ [2016-09-26 06:34:43] secresearch at fortinet dot com The patch must looks like this: --- PHP-5.6.26_old/ext/mbstring/libmbfl/mbfl/mbfilter.c 2016-09-26 11:54:21.369998637 +0800 +++ PHP-5.6.26/ext/mbstring/libmbfl/mbfl/mbfilter.c 2016-09-26 14:32:27.536978132 +0800 @@ -111,6 +111,7 @@ 0x30,0x31,0x32,0x33,0x34,0x35,0x36,0x37,0x38,0x39,0x41,0x42,0x43,0x44,0x45,0x46 }; +#define INT_MAX_LIMIT ((1UL << (SIZEOF_INT * 8 - 1)) - 1) /* @@ -3042,7 +3043,7 @@ int n; unsigned char *p; - if (string == NULL || result == NULL) { + if (string == NULL || result == NULL || (string->len > INT_MAX_LIMIT/5)) { return NULL; } mbfl_string_init(result); output_len <= input_len*5 (5 times is the maximum output length, this depend on convmap, type of encode. So I just leave 5 here for quick fix) ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=73082 -- Edit this bug report at https://bugs.php.net/bug.php?id=73082&edit=1

« previous php.bugs (#207332) next »