Sec Bug->Bug #72975 [Csd]: ldap_escape could produce string larger than 2Gb

From: Date: Mon, 13 Feb 2017 01:25:35 +0000
Subject: Sec Bug->Bug #72975 [Csd]: ldap_escape could produce string larger than 2Gb
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-207338@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72975&edit=1 ID: 72975 Updated by: stas@php.net Reported by: nguyenluan dot vnn at gmail dot com Summary: ldap_escape could produce string larger than 2Gb Status: Closed -Type: Security +Type: Bug Package: LDAP related PHP Version: 5.6.25 Assigned To: stas Block user comment: N Private report: N Previous Comments: ------------------------------------------------------------------------ [2016-09-14 14:01:45] nguyenluan dot vnn at gmail dot com But in this bug https://bugs.php.net/bug.php?id=72513, running without memory limit and opening large path name still have CVE number. ------------------------------------------------------------------------ [2016-09-13 16:59:52] stas@php.net I don't think this needs a CVE. Running without memory limit in production and escaping user-suppied 2G string does not look like a common scenario. Same for all other non-memory-limit issues. ------------------------------------------------------------------------ [2016-09-13 12:36:12] nguyenluan dot vnn at gmail dot com Can you assign a CVE number for this? ------------------------------------------------------------------------ [2016-09-13 04:12:35] stas@php.net The fix for this bug has been committed. Snapshots of the sources are packaged every three hours; this change will be in the next snapshot. You can grab the snapshot at http://snaps.php.net/. For Windows: http://windows.php.net/snapshots/ Thank you for the report, and for helping us make PHP better. ------------------------------------------------------------------------ [2016-09-02 16:06:31] nguyenluan dot vnn at gmail dot com The patch is good. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=72975 -- Edit this bug report at https://bugs.php.net/bug.php?id=72975&edit=1

« previous php.bugs (#207338) next »