Bug #75934 [Com]: Out of Bound in sodium_pad

From: Date: Sun, 29 Apr 2018 17:33:26 +0000
Subject: Bug #75934 [Com]: Out of Bound in sodium_pad
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-214980@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=75934&edit=1

 ID:                 75934
 Comment by:         jedisct1@php.net
 Reported by:        zhihua dot yao at dbappsecurity dot com dot cn
 Summary:            Out of Bound in sodium_pad
 Status:             Assigned
 Type:               Bug
 Package:            Reproducible crash
 PHP Version:        7.2.2
 Assigned To:        jedisct1
 Block user comment: N
 Private report:     N

 New Comment:

This can be downplayed by pointing out the fact that
ini_set('memory_limit',-1); is not a thing to allow on untrusted
data/scripts. 

But altering the memory_limit value may not be required to trigger this overflow.


Previous Comments:
------------------------------------------------------------------------
[2018-04-29 17:30:18] jedisct1@php.net

I'd consider this a security issue. Which is trivial to trigger:

ini_set('memory_limit',-1);
$a = str_repeat('x', 2147483647);
$b = $a . $a;

------------------------------------------------------------------------
[2018-04-29 12:57:54] zhihua dot yao at dbappsecurity dot com dot cn

Okay, is this a security issue?I really do not understand the classification of your security
issues. Some of them I believe are not classified as security issues,but classified as security
issues.

------------------------------------------------------------------------
[2018-04-28 14:37:49] jedisct1@php.net

Workaround: https://github.com/jedisct1/libsodium-php/commit/75701f246f44911ca9cd559341c827538f563d24

But the root cause should rather be fixed.

------------------------------------------------------------------------
[2018-04-28 14:13:38] jedisct1@php.net

zend_string_alloc() is broken due to the absence of overflow check before rounding; if the requested
length is >= SIZE_MAX-16, it allocates either 0 or 16 bytes, and returns a valid pointer instead
of an OOM.

------------------------------------------------------------------------
[2018-04-28 00:52:09] zhihua dot yao at dbappsecurity dot com dot cn

However, I was using the latest version. When I compiled the sodium, this poc would cause a
crash.Maybe it has been fixed?

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=75934


--
Edit this bug report at https://bugs.php.net/bug.php?id=75934&edit=1


Thread (16 messages)

« previous php.bugs (#214980) next »