Bug #76155 [Opn->Csd]: Integer overflow

From: Date: Mon, 23 Apr 2018 04:30:23 +0000
Subject: Bug #76155 [Opn->Csd]: Integer overflow
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-214835@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76155&edit=1

 ID:                 76155
 Updated by:         stas@php.net
 Reported by:        jmenon at isi dot edu
 Summary:            Integer overflow
-Status:             Open
+Status:             Closed
 Type:               Bug
 Package:            PHAR related
 Operating System:   Linux
 PHP Version:        7.2Git-2018-03-27 (Git)
-Assigned To:        
+Assigned To:        stas
 Block user comment: N
 Private report:     N

 New Comment:

The fix for this bug has been committed.

Snapshots of the sources are packaged every three hours; this change
will be in the next snapshot. You can grab the snapshot at
http://snaps.php.net/.

 For Windows:

http://windows.php.net/snapshots/
 
Thank you for the report, and for helping us make PHP better.




Previous Comments:
------------------------------------------------------------------------
[2018-04-23 03:26:43] stas@php.net

Doesn't seem to have any security implications, but probably worth fixing anyway since
it's not nice to convert size_t to int and then forget it can be negative.

------------------------------------------------------------------------
[2018-03-27 23:11:10] jmenon at isi dot edu

Description:
------------
There exists a signed comparison happening in the phar_check_str() @ phar.c : 1857 which can be
bypassed with a negative value and could lead to a buffer-over-flow on the stack with user
controlled input.

This is not an exploitable bug due to a comparison happening in the phar_split_fname() @ phar.c :
2209 which sign extends the int variable to size_t.

We do not believe that this is the intended consequence of the above mentioned comparison and
therefore, it might be possible to exploit this vulnerability in a situation where PHP (32 bit)
allows generation of strings of size larger than 2^31 bytes.

We had reported this bug via email, but did not receive any response after 5 days which is why we
chose to report it here as well.

Test script:
---------------
phar_check_str():

1854 : char test[51];

1857 : if ( ext_len >= 50)
               return FAILURE;

1863 : memcpy(test, ext_str - 1, ext_len + 1);

...
phar_split_fname():

2209 : if (CHECK_NULL_PATH(filename, filename_len)) 
           return FAILURE;
...
zend_API.h

#define CHECK_NULL_PATH(p, l) (strlen(p) != (size_t)(l))



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=76155&edit=1


Thread (1 message)

  • stas@php.net
  • Unknown Message
    • stas@php.net
« previous php.bugs (#214835) next »