Sec Bug->Bug #72975 [Csd]: ldap_escape could produce string larger than 2Gb
| From: | stas@php.net | Date: | Mon, 13 Feb 2017 01:25:35 +0000 |
| Subject: | Sec Bug->Bug #72975 [Csd]: ldap_escape could produce string larger than 2Gb | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-207338@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=72975&edit=1
ID: 72975
Updated by: stas@php.net
Reported by: nguyenluan dot vnn at gmail dot com
Summary: ldap_escape could produce string larger than 2Gb
Status: Closed
-Type: Security
+Type: Bug
Package: LDAP related
PHP Version: 5.6.25
Assigned To: stas
Block user comment: N
Private report: N
Previous Comments:
------------------------------------------------------------------------
[2016-09-14 14:01:45] nguyenluan dot vnn at gmail dot com
But in this bug https://bugs.php.net/bug.php?id=72513, running
without memory limit and opening large path name still have CVE number.
------------------------------------------------------------------------
[2016-09-13 16:59:52] stas@php.net
I don't think this needs a CVE. Running without memory limit in production and escaping
user-suppied 2G string does not look like a common scenario. Same for all other non-memory-limit
issues.
------------------------------------------------------------------------
[2016-09-13 12:36:12] nguyenluan dot vnn at gmail dot com
Can you assign a CVE number for this?
------------------------------------------------------------------------
[2016-09-13 04:12:35] stas@php.net
The fix for this bug has been committed.
Snapshots of the sources are packaged every three hours; this change
will be in the next snapshot. You can grab the snapshot at
http://snaps.php.net/.
For Windows:
http://windows.php.net/snapshots/
Thank you for the report, and for helping us make PHP better.
------------------------------------------------------------------------
[2016-09-02 16:06:31] nguyenluan dot vnn at gmail dot com
The patch is good.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=72975
--
Edit this bug report at https://bugs.php.net/bug.php?id=72975&edit=1