Sec Bug->Bug #72807 [Csd]: integer overflow in curl_escape caused heap corruption
| From: | stas@php.net | Date: | Mon, 13 Feb 2017 01:46:20 +0000 |
| Subject: | Sec Bug->Bug #72807 [Csd]: integer overflow in curl_escape caused heap corruption | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-207358@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=72807&edit=1
ID: 72807
Updated by: stas@php.net
Reported by: minhrau dot vc dot 365 at gmail dot com
Summary: integer overflow in curl_escape caused heap
corruption
Status: Closed
-Type: Security
+Type: Bug
Package: cURL related
Operating System: ALL
PHP Version: 5.6.24
Assigned To: stas
Block user comment: N
Private report: N
Previous Comments:
------------------------------------------------------------------------
[2016-08-17 06:43:56] stas@php.net
The fix for this bug has been committed.
Snapshots of the sources are packaged every three hours; this change
will be in the next snapshot. You can grab the snapshot at
http://snaps.php.net/.
For Windows:
http://windows.php.net/snapshots/
Thank you for the report, and for helping us make PHP better.
------------------------------------------------------------------------
[2016-08-15 04:11:54] minhrau dot vc dot 365 at gmail dot com
Patch bd9d2292ba1913bffe058e1245c7f28622d1b1bb had been fixed this issue.
------------------------------------------------------------------------
[2016-08-15 02:40:53] minhrau dot vc dot 365 at gmail dot com
Ok, it's weird.
Can I ask a CVE-ID for this?
------------------------------------------------------------------------
[2016-08-13 19:09:04] stas@php.net
PHP 5.6 does not support stings which are longer that integer can accommodate. No function should
produce these strings. That's the meaning of the patch. There's no point in checking for
negative length in the string, because there should be no such thing in PHP. Due to bug in
curl_escape, such thing was produced, and now it's fixed.
------------------------------------------------------------------------
[2016-08-13 10:53:53] minhrau dot vc dot 365 at gmail dot com
guys,
I think you missed the point here!
You weren't fix the vulnerability, you just tried to limit the function that create long
string. There are nothing called "string with negative length", the negative length was
existing because your code, in this case is in json_decode function, calculate wrong the length of
input string, and it also not check the length before its processing.
My suggestion here is fix the actually code that missing the check (in function php_json_decode_ex)
above, do not try to kill all functions create long strings.
I disagree with your patch
Regards.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=72807
--
Edit this bug report at https://bugs.php.net/bug.php?id=72807&edit=1