Bug #76319 [Ana]: mb_strtolower with default encoding causes BufferOverflow and termination

From: Date: Thu, 24 May 2018 21:27:32 +0000
Subject: Bug #76319 [Ana]: mb_strtolower with default encoding causes BufferOverflow and termination
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-215361@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76319&edit=1 ID: 76319 Updated by: cmb@php.net Reported by: ion dot bazan at gmail dot com Summary: mb_strtolower with default encoding causes BufferOverflow and termination Status: Analyzed Type: Bug Package: mbstring related Operating System: Linux PHP Version: master-Git-2018-05-09 (Git) Block user comment: N Private report: N New Comment: BTW: doesn't the implementation of full case mapping[1] deserve a prominent entry in UPGRADING? [1] <http://git.php.net/?p=php-src.git;a=commit;h=582a65b06f3de125887cab02d5c561168fcf94bc> Previous Comments: ------------------------------------------------------------------------ [2018-05-09 19:10:30] nikic@php.net We're getting 0x780000a1 as the character, the simple casemapping leaves it at 0x780000a1, but the full casemapping assigns special meaning to results that have a non-zero top byte. We'll have to add an explicit check for out of range characters before calling the casemapping functions. ------------------------------------------------------------------------ [2018-05-09 19:00:36] nikic@php.net <?php var_dump(mb_strtolower("a\xA1\x0B", 'UTF-8')); UTF-8 is the default encoding and \xA1\x0B is invalid UTF-8. Clearly something is going wrong with handling invalid UTF-8. ------------------------------------------------------------------------ [2018-05-09 18:50:42] ion dot bazan at gmail dot com Calling: mb_strtolower(urldecode('a%A1%C0b'), 'ASCII') works properly though. ------------------------------------------------------------------------ [2018-05-09 18:46:36] ion dot bazan at gmail dot com Change category ------------------------------------------------------------------------ [2018-05-09 18:44:25] ion dot bazan at gmail dot com Description: ------------ Calling mb_strtolower without specifying the encoding may cause unexpected buffer overflow while on PHP 7.2 it works properly. Test script: --------------- var_dump(mb_strtolower(urldecode('a%A1%C0b'))); Expected result: ---------------- string(4) "a??b" Actual result: -------------- *** buffer overflow detected ***: php terminated ======= Backtrace: ========= /lib/x86_64-linux-gnu/libc.so.6(+0x7329f)[0x7f3bc3f2f29f] /lib/x86_64-linux-gnu/libc.so.6(__fortify_fail+0x5c)[0x7f3bc3fca83c] /lib/x86_64-linux-gnu/libc.so.6(+0x10d710)[0x7f3bc3fc9710] php[0x6f8f6d] php[0x6e8031] php(php_unicode_convert_case+0xbd)[0x6f917d] php[0x6f26c3] php(execute_ex+0x8e25)[0x9d15e5] php(zend_call_function+0x7de)[0x92533e] php[0x76fdba] php(execute_ex+0x8e25)[0x9d15e5] php(zend_execute+0x1d6)[0x9d26c6] php(zend_execute_scripts+0xe7)[0x9366f7] php(php_execute_script+0x3a6)[0x8c7116] php[0x9d4cda] php[0x45e8d0] --- CUT --- ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=76319&edit=1

« previous php.bugs (#215361) next »