Sec Bug->Bug #72782 [Csd]: Heap Overflow due to integer overflows

From: Date: Mon, 13 Feb 2017 01:46:12 +0000
Subject: Sec Bug->Bug #72782 [Csd]: Heap Overflow due to integer overflows
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-207357@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72782&edit=1 ID: 72782 Updated by: stas@php.net Reported by: loianhtuan at gmail dot com Summary: Heap Overflow due to integer overflows Status: Closed -Type: Security +Type: Bug Package: mcrypt related PHP Version: 7.0.9 Assigned To: stas Block user comment: N Private report: N Previous Comments: ------------------------------------------------------------------------ [2016-08-17 08:34:30] stas@php.net The fix for this bug has been committed. Snapshots of the sources are packaged every three hours; this change will be in the next snapshot. You can grab the snapshot at http://snaps.php.net/. For Windows: http://windows.php.net/snapshots/ Thank you for the report, and for helping us make PHP better. ------------------------------------------------------------------------ [2016-08-11 06:29:07] loianhtuan at gmail dot com Hi I have verified. It works! Thanks! ------------------------------------------------------------------------ [2016-08-11 05:40:40] stas@php.net Patch in https://gist.github.com/3b95740f9008e008b0c6f202e410d996 should fix it (also 4f6a97f5321ef617b98a1f79aac1ad447d13b2b4 in security repo). Please verify. ------------------------------------------------------------------------ [2016-08-11 05:32:19] loianhtuan at gmail dot com Some can ask the same question: why it should be int? Negative value means nothing here. So I prefer size_t for future proof. Btw, it's up to you. :D ------------------------------------------------------------------------ [2016-08-11 05:23:12] stas@php.net Not sure why block_size should be size_t... I have never seen a block cypher with blocks so huge it doesn't fit into int. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=72782 -- Edit this bug report at https://bugs.php.net/bug.php?id=72782&edit=1

« previous php.bugs (#207357) next »