Bug #75691 [Fbk->Nab]: off by one overflow

From: Date: Fri, 15 Dec 2017 18:40:54 +0000
Subject: Bug #75691 [Fbk->Nab]: off by one overflow
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-213122@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=75691&edit=1 ID: 75691 Updated by: ab@php.net Reported by: YangX92 at hotmail dot com Summary: off by one overflow -Status: Feedback +Status: Not a bug Type: Bug Package: PHAR related Operating System: Linux PHP Version: 7.2Git-2017-12-15 (Git) Block user comment: N Private report: N New Comment: @YangX92 at hotmail dot com so is it, it's char[8] and is always used with sizeof. Thanks. Previous Comments: ------------------------------------------------------------------------ [2017-12-15 09:14:04] Yangx92 at hotmail dot com I think the size should be len+1. If you think save is just the char array, there is no bug. ------------------------------------------------------------------------ [2017-12-15 08:26:18] requinix@php.net > the char array should be terminated by the NULL character Why? It's a temporary array, not a string. ------------------------------------------------------------------------ [2017-12-15 08:18:44] YangX92 at hotmail dot com Description: ------------ There is a off-by-one overflow in phar_is_tar function in ext/phar/tar.c. >>> char save[sizeof(header->checksum)], *bname; /* assume that the first filename in a tar won't begin with <?php */ if (!strncmp(buf, "<?php", sizeof("<?php")-1)) { return 0; } memcpy(save, header->checksum, sizeof(header->checksum)); memset(header->checksum, ' ', sizeof(header->checksum)); >>> As code show above, the length of save should be sizeof(header->checksum)+1. Because, the char array should be terminated by the NULL character. Test script: --------------- No Expected result: ---------------- No Actual result: -------------- No ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=75691&edit=1

« previous php.bugs (#213122) next »