Edit report at https://bugs.php.net/bug.php?id=76155&edit=1
ID: 76155
Updated by: stas@php.net
Reported by: jmenon at isi dot edu
Summary: Integer overflow
Status: Open
-Type: Security
+Type: Bug
Package: PHAR related
Operating System: Linux
PHP Version: 7.2Git-2018-03-27 (Git)
Block user comment: N
Private report: Y
New Comment:
Doesn't seem to have any security implications, but probably worth fixing anyway since
it's not nice to convert size_t to int and then forget it can be negative.
Previous Comments:
------------------------------------------------------------------------
[2018-03-27 23:11:10] jmenon at isi dot edu
Description:
------------
There exists a signed comparison happening in the phar_check_str() @ phar.c : 1857 which can be
bypassed with a negative value and could lead to a buffer-over-flow on the stack with user
controlled input.
This is not an exploitable bug due to a comparison happening in the phar_split_fname() @ phar.c :
2209 which sign extends the int variable to size_t.
We do not believe that this is the intended consequence of the above mentioned comparison and
therefore, it might be possible to exploit this vulnerability in a situation where PHP (32 bit)
allows generation of strings of size larger than 2^31 bytes.
We had reported this bug via email, but did not receive any response after 5 days which is why we
chose to report it here as well.
Test script:
---------------
phar_check_str():
1854 : char test[51];
1857 : if ( ext_len >= 50)
return FAILURE;
1863 : memcpy(test, ext_str - 1, ext_len + 1);
...
phar_split_fname():
2209 : if (CHECK_NULL_PATH(filename, filename_len))
return FAILURE;
...
zend_API.h
#define CHECK_NULL_PATH(p, l) (strlen(p) != (size_t)(l))
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=76155&edit=1