Edit report at https://bugs.php.net/bug.php?id=75934&edit=1
ID: 75934
Comment by: spam2 at rhsoft dot net
Reported by: zhihua dot yao at dbappsecurity dot com dot cn
Summary: Out of Bound in sodium_pad
Status: Assigned
Type: Bug
Package: Reproducible crash
PHP Version: 7.2.2
Assigned To: jedisct1
Block user comment: N
Private report: N
New Comment:
https://wiki.php.net/security
We do not classify as a security issue any issue that:
requires invocation of specific code, which may be valid but is obviously malicious
requires invocation of functions with specific arguments, which may be valid but are obviously
malicious
requires specific actions to be performed on the server, which are not commonly performed, or are
not commonly permissible for the user (uid) executing PHP
requires privileges superior to that of the user (uid) executing PHP
requires the use of debugging facilities - ex. xdebug, var_dump
requires the use of settings not recommended for production - ex. error reporting to output
requires the use of non-standard environment variables - ex. USE_ZEND_ALLOC
requires the use of non-standard builds - ex. obscure embedded platform, not commonly used compiler
requires the use of code or settings known to be insecure
Previous Comments:
------------------------------------------------------------------------
[2018-04-29 17:36:23] spam2 at rhsoft dot net
sadly the php-developers typically don't consider something which needs to be triggered with
code like yours or whatever triggers a OOM as security issue
there are many bug reports in the recent past "just verify your input" classified
------------------------------------------------------------------------
[2018-04-29 17:33:23] jedisct1@php.net
This can be downplayed by pointing out the fact that
ini_set('memory_limit',-1); is not a thing to allow on untrusted
data/scripts.
But altering the memory_limit value may not be required to trigger this overflow.
------------------------------------------------------------------------
[2018-04-29 17:30:18] jedisct1@php.net
I'd consider this a security issue. Which is trivial to trigger:
ini_set('memory_limit',-1);
$a = str_repeat('x', 2147483647);
$b = $a . $a;
------------------------------------------------------------------------
[2018-04-29 12:57:54] zhihua dot yao at dbappsecurity dot com dot cn
Okay, is this a security issue?I really do not understand the classification of your security
issues. Some of them I believe are not classified as security issues,but classified as security
issues.
------------------------------------------------------------------------
[2018-04-28 14:37:49] jedisct1@php.net
Workaround: https://github.com/jedisct1/libsodium-php/commit/75701f246f44911ca9cd559341c827538f563d24
But the root cause should rather be fixed.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=75934
--
Edit this bug report at https://bugs.php.net/bug.php?id=75934&edit=1