Edit report at https://bugs.php.net/bug.php?id=74096&edit=1
ID: 74096
Updated by: stas@php.net
Reported by: cyoung at tripwire dot com
Summary: Unserialize Possible integer overflow in memory
allocation
-Status: Open
+Status: Not a bug
-Type: Security
+Type: Bug
Package: *Programming Data Structures
Operating System: Linux (4.4.0-59-generic)
PHP Version: 7.1.2RC1
Block user comment: N
Private report: Y
New Comment:
Don't see an issue here. Looks to be intended behavior, and erroring out on bad data is ok.
Previous Comments:
------------------------------------------------------------------------
[2017-02-14 21:28:28] cyoung at tripwire dot com
Description:
------------
It seems like this is a properly handled situation in 7.1.2RC1, but in older versions, there is no
Fatal Error making me question if there may be a problem with older PHP (such as version PHP 5.6.17
(cli) (built: Jan 8 2016 10:27:48)).
Unserializing some crafted data leads to this error:
php -r
"unserialize('a:1:{i:0;O:1:\"H\":01{}i:0;O:1:\"a\":01{yi:0;O:1:\"a\":3000000000{}i:');"
PHP Fatal error: Possible integer overflow in memory allocation (3000000001 * 32 + 32) in Command
line code on line 1
I am submitting this as a security bug so that someone with better knowledge of PHP internals can
make sure this is safe behavior.
Test script:
---------------
php -r
"unserialize('a:1:{i:0;O:1:\"H\":01{}i:0;O:1:\"a\":01{yi:0;O:1:\"a\":3000000000{}i:');"
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=74096&edit=1