Sec Bug->Bug #74096 [Opn->Nab]: Unserialize Possible integer overflow in memory allocation

From: Date: Tue, 14 Feb 2017 21:35:47 +0000
Subject: Sec Bug->Bug #74096 [Opn->Nab]: Unserialize Possible integer overflow in memory allocation
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-207380@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=74096&edit=1

 ID:                 74096
 Updated by:         stas@php.net
 Reported by:        cyoung at tripwire dot com
 Summary:            Unserialize Possible integer overflow in memory
                     allocation
-Status:             Open
+Status:             Not a bug
-Type:               Security
+Type:               Bug
 Package:            *Programming Data Structures
 Operating System:   Linux (4.4.0-59-generic)
 PHP Version:        7.1.2RC1
 Block user comment: N
 Private report:     Y

 New Comment:

Don't see an issue here. Looks to be intended behavior, and erroring out on bad data is ok.


Previous Comments:
------------------------------------------------------------------------
[2017-02-14 21:28:28] cyoung at tripwire dot com

Description:
------------
It seems like this is a properly handled situation in 7.1.2RC1, but in older versions, there is no
Fatal Error making me question if there may be a problem with older PHP (such as version PHP 5.6.17
(cli) (built: Jan  8 2016 10:27:48)).

Unserializing some crafted data leads to this error:
php -r
"unserialize('a:1:{i:0;O:1:\"H\":01{}i:0;O:1:\"a\":01{yi:0;O:1:\"a\":3000000000{}i:');"
PHP Fatal error:  Possible integer overflow in memory allocation (3000000001 * 32 + 32) in Command
line code on line 1

I am submitting this as a security bug so that someone with better knowledge of PHP internals can
make sure this is safe behavior.

Test script:
---------------
php -r
"unserialize('a:1:{i:0;O:1:\"H\":01{}i:0;O:1:\"a\":01{yi:0;O:1:\"a\":3000000000{}i:');"



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=74096&edit=1


Thread (1 message)

  • stas@php.net
  • Unknown Message
    • stas@php.net
« previous php.bugs (#207380) next »