Sec Bug->Bug #72807 [Csd]: integer overflow in curl_escape caused heap corruption

From: Date: Mon, 13 Feb 2017 01:46:20 +0000
Subject: Sec Bug->Bug #72807 [Csd]: integer overflow in curl_escape caused heap corruption
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-207358@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72807&edit=1 ID: 72807 Updated by: stas@php.net Reported by: minhrau dot vc dot 365 at gmail dot com Summary: integer overflow in curl_escape caused heap corruption Status: Closed -Type: Security +Type: Bug Package: cURL related Operating System: ALL PHP Version: 5.6.24 Assigned To: stas Block user comment: N Private report: N Previous Comments: ------------------------------------------------------------------------ [2016-08-17 06:43:56] stas@php.net The fix for this bug has been committed. Snapshots of the sources are packaged every three hours; this change will be in the next snapshot. You can grab the snapshot at http://snaps.php.net/. For Windows: http://windows.php.net/snapshots/ Thank you for the report, and for helping us make PHP better. ------------------------------------------------------------------------ [2016-08-15 04:11:54] minhrau dot vc dot 365 at gmail dot com Patch bd9d2292ba1913bffe058e1245c7f28622d1b1bb had been fixed this issue. ------------------------------------------------------------------------ [2016-08-15 02:40:53] minhrau dot vc dot 365 at gmail dot com Ok, it's weird. Can I ask a CVE-ID for this? ------------------------------------------------------------------------ [2016-08-13 19:09:04] stas@php.net PHP 5.6 does not support stings which are longer that integer can accommodate. No function should produce these strings. That's the meaning of the patch. There's no point in checking for negative length in the string, because there should be no such thing in PHP. Due to bug in curl_escape, such thing was produced, and now it's fixed. ------------------------------------------------------------------------ [2016-08-13 10:53:53] minhrau dot vc dot 365 at gmail dot com guys, I think you missed the point here! You weren't fix the vulnerability, you just tried to limit the function that create long string. There are nothing called "string with negative length", the negative length was existing because your code, in this case is in json_decode function, calculate wrong the length of input string, and it also not check the length before its processing. My suggestion here is fix the actually code that missing the check (in function php_json_decode_ex) above, do not try to kill all functions create long strings. I disagree with your patch Regards. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=72807 -- Edit this bug report at https://bugs.php.net/bug.php?id=72807&edit=1

« previous php.bugs (#207358) next »