Edit report at https://bugs.php.net/bug.php?id=75934&edit=1
ID: 75934
Comment by: spam2 at rhsoft dot net
Reported by: zhihua dot yao at dbappsecurity dot com dot cn
Summary: Out of Bound in sodium_pad
Status: Assigned
Type: Bug
Package: Reproducible crash
PHP Version: 7.2.2
Assigned To: jedisct1
Block user comment: N
Private report: N
New Comment:
sadly the php-developers typically don't consider something which needs to be triggered with
code like yours or whatever triggers a OOM as security issue
there are many bug reports in the recent past "just verify your input" classified
Previous Comments:
------------------------------------------------------------------------
[2018-04-29 17:33:23] jedisct1@php.net
This can be downplayed by pointing out the fact that
ini_set('memory_limit',-1); is not a thing to allow on untrusted
data/scripts.
But altering the memory_limit value may not be required to trigger this overflow.
------------------------------------------------------------------------
[2018-04-29 17:30:18] jedisct1@php.net
I'd consider this a security issue. Which is trivial to trigger:
ini_set('memory_limit',-1);
$a = str_repeat('x', 2147483647);
$b = $a . $a;
------------------------------------------------------------------------
[2018-04-29 12:57:54] zhihua dot yao at dbappsecurity dot com dot cn
Okay, is this a security issue?I really do not understand the classification of your security
issues. Some of them I believe are not classified as security issues,but classified as security
issues.
------------------------------------------------------------------------
[2018-04-28 14:37:49] jedisct1@php.net
Workaround: https://github.com/jedisct1/libsodium-php/commit/75701f246f44911ca9cd559341c827538f563d24
But the root cause should rather be fixed.
------------------------------------------------------------------------
[2018-04-28 14:13:38] jedisct1@php.net
zend_string_alloc() is broken due to the absence of overflow check before rounding; if the requested
length is >= SIZE_MAX-16, it allocates either 0 or 16 bytes, and returns a valid pointer instead
of an OOM.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=75934
--
Edit this bug report at https://bugs.php.net/bug.php?id=75934&edit=1