Bug #75575 [Opn->Csd]: Theoretical pointer wrapping and access-out-of-bounds in non-standard Zend code

From: Date: Tue, 28 Nov 2017 22:13:32 +0000
Subject: Bug #75575 [Opn->Csd]: Theoretical pointer wrapping and access-out-of-bounds in non-standard Zend code
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-212783@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=75575&edit=1 ID: 75575 Updated by: nikic@php.net Reported by: plebbyastian at gmail dot com Summary: Theoretical pointer wrapping and access-out-of-bounds in non-standard Zend code -Status: Open +Status: Closed Type: Bug Package: *General Issues Operating System: Whatever PHP Version: Irrelevant Block user comment: N Private report: N New Comment: Automatic comment on behalf of nikita.ppv@gmail.com Revision: http://git.php.net/?p=php-src.git;a=commit;h=5dc6392d257fa8a4c3a8938e9e0e36ae44a6834e Log: Fixed bug #75575 Previous Comments: ------------------------------------------------------------------------ [2017-11-26 23:14:29] plebbyastian at gmail dot com Description: ------------ The subtraction at <https://github.com/php/php-src/blob/26f8fc833b9668a8b8e14ecd7d94930146019adb/Zend/zend_operators.c#L3059> has no guard to ensure pointer wrapping (which itself is undefined behaviour) doesn't occur. There's an identical unguarded pointer subtraction at <https://github.com/php/php-src/blob/26f8fc833b9668a8b8e14ecd7d94930146019adb/Zend/zend_operators.c#L3093>. Successful exploitation would result in high ranges of memory becoming accessible to the attacker, with similar usecases to heartbleed. Remember this when you try to argue for use of non-standard, reinvented wheels. Testing incurs a price. As does code complexity. To put my "standardisation" rants into perspective, here's how C11/6.5.6p8 defines PHP: > ... If both the pointer operand and the result point to elements of the same array object, or > one past the last element of the array object, the evaluation shall not produce an overflow; > otherwise, the behavior is undefined. ... ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=75575&edit=1

« previous php.bugs (#212783) next »