Bug #67619 [Opn->Ver]: Length parameters in socket_write() etc. may be negative

From: Date: Mon, 26 Mar 2018 13:25:21 +0000
Subject: Bug #67619 [Opn->Ver]: Length parameters in socket_write() etc. may be negative
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-214485@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=67619&edit=1

 ID:                 67619
 Updated by:         cmb@php.net
 Reported by:        tstarling@php.net
 Summary:            Length parameters in socket_write() etc. may be
                     negative
-Status:             Open
+Status:             Verified
 Type:               Bug
 Package:            Sockets related
 Operating System:   Linux
-PHP Version:        5.6Git-2014-07-14 (Git)
+PHP Version:        7.2.4
 Block user comment: N
 Private report:     N



Previous Comments:
------------------------------------------------------------------------
[2014-07-14 22:54:27] tstarling@php.net

Description:
------------
In socket_write(), socket_send() and socket_sendto(), it is not checked whether the length parameter
is negative. If it is negative, it will be converted to a size_t for the underlying syscall, so a
write of more than 2GB will be requested. In my testing, this fails with EFAULT. It is conceivable
that it may instead be a buffer overflow on some embedded systems.

I suggest validating the length parameter.

Test script:
---------------
$f = socket_create(AF_INET, SOCK_STREAM,  SOL_TCP);
socket_connect($f, '127.0.0.1',8888);
socket_write($f, "Hello\n", -1);


Actual result:
--------------
Warning: socket_write(): unable to write to socket [14]: Bad address



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=67619&edit=1


Thread (3 messages)

« previous php.bugs (#214485) next »