Bug #75686 [Opn->Nab]: coding bug

From: Date: Thu, 14 Dec 2017 15:02:28 +0000
Subject: Bug #75686 [Opn->Nab]: coding bug
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-213098@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=75686&edit=1 ID: 75686 Updated by: requinix@php.net Reported by: yangx92 at hotmail dot com Summary: coding bug -Status: Open +Status: Not a bug Type: Bug Package: XML Writer Operating System: Linux PHP Version: master-Git-2017-12-14 (Git) Block user comment: N Private report: N New Comment: Path length is checked during VCWD_REALPATH. Previous Comments: ------------------------------------------------------------------------ [2017-12-14 12:19:04] yangx92 at hotmail dot com Description: ------------ There is a coding bug in _xmlwriter_get_valid_file_path function in ext/xmlwriter/php_xmlwriter.c. >>> char file_dirname[MAXPATHLEN]; size_t dir_len; if (!VCWD_REALPATH(source, resolved_path) && !expand_filepath(source, resolved_path)) { xmlFreeURI(uri); return NULL; } memcpy(file_dirname, source, strlen(source)); >>> As code showed above, I think there should be a check for strlen(source) and MAXPATHLEN. If strlen(source) >= MAXPATHLEN, there will be a buffer overflow. Test script: --------------- None Expected result: ---------------- None Actual result: -------------- None ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=75686&edit=1

« previous php.bugs (#213098) next »