Bug #75686 [Opn->Nab]: coding bug
| From: | requinix@php.net | Date: | Thu, 14 Dec 2017 15:02:28 +0000 |
| Subject: | Bug #75686 [Opn->Nab]: coding bug | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-213098@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=75686&edit=1
ID: 75686
Updated by: requinix@php.net
Reported by: yangx92 at hotmail dot com
Summary: coding bug
-Status: Open
+Status: Not a bug
Type: Bug
Package: XML Writer
Operating System: Linux
PHP Version: master-Git-2017-12-14 (Git)
Block user comment: N
Private report: N
New Comment:
Path length is checked during VCWD_REALPATH.
Previous Comments:
------------------------------------------------------------------------
[2017-12-14 12:19:04] yangx92 at hotmail dot com
Description:
------------
There is a coding bug in _xmlwriter_get_valid_file_path function in ext/xmlwriter/php_xmlwriter.c.
>>>
char file_dirname[MAXPATHLEN];
size_t dir_len;
if (!VCWD_REALPATH(source, resolved_path) && !expand_filepath(source,
resolved_path)) {
xmlFreeURI(uri);
return NULL;
}
memcpy(file_dirname, source, strlen(source));
>>>
As code showed above, I think there should be a check for strlen(source) and MAXPATHLEN. If
strlen(source) >= MAXPATHLEN, there will be a buffer overflow.
Test script:
---------------
None
Expected result:
----------------
None
Actual result:
--------------
None
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=75686&edit=1