Bug #75691 [Opn->Fbk]: off by one overflow
| From: | requinix@php.net | Date: | Fri, 15 Dec 2017 08:26:19 +0000 |
| Subject: | Bug #75691 [Opn->Fbk]: off by one overflow | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-213113@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=75691&edit=1
ID: 75691
Updated by: requinix@php.net
Reported by: YangX92 at hotmail dot com
Summary: off by one overflow
-Status: Open
+Status: Feedback
Type: Bug
Package: PHAR related
Operating System: Linux
PHP Version: 7.2Git-2017-12-15 (Git)
Block user comment: N
Private report: N
New Comment:
> the char array should be terminated by the NULL character
Why? It's a temporary array, not a string.
Previous Comments:
------------------------------------------------------------------------
[2017-12-15 08:18:44] YangX92 at hotmail dot com
Description:
------------
There is a off-by-one overflow in phar_is_tar function in ext/phar/tar.c.
>>>
char save[sizeof(header->checksum)], *bname;
/* assume that the first filename in a tar won't begin with <?php */
if (!strncmp(buf, "<?php", sizeof("<?php")-1)) {
return 0;
}
memcpy(save, header->checksum, sizeof(header->checksum));
memset(header->checksum, ' ', sizeof(header->checksum));
>>>
As code show above, the length of save should be sizeof(header->checksum)+1. Because, the char
array should be terminated by the NULL character.
Test script:
---------------
No
Expected result:
----------------
No
Actual result:
--------------
No
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=75691&edit=1