Bug #76319 [Ana]: mb_strtolower with default encoding causes BufferOverflow and termination
| From: | cmb@php.net | Date: | Thu, 24 May 2018 21:27:32 +0000 |
| Subject: | Bug #76319 [Ana]: mb_strtolower with default encoding causes BufferOverflow and termination | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-215361@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=76319&edit=1
ID: 76319
Updated by: cmb@php.net
Reported by: ion dot bazan at gmail dot com
Summary: mb_strtolower with default encoding causes
BufferOverflow and termination
Status: Analyzed
Type: Bug
Package: mbstring related
Operating System: Linux
PHP Version: master-Git-2018-05-09 (Git)
Block user comment: N
Private report: N
New Comment:
BTW: doesn't the implementation of full case mapping[1] deserve a
prominent entry in UPGRADING?
[1] <http://git.php.net/?p=php-src.git;a=commit;h=582a65b06f3de125887cab02d5c561168fcf94bc>
Previous Comments:
------------------------------------------------------------------------
[2018-05-09 19:10:30] nikic@php.net
We're getting 0x780000a1 as the character, the simple casemapping leaves it at 0x780000a1, but
the full casemapping assigns special meaning to results that have a non-zero top byte. We'll
have to add an explicit check for out of range characters before calling the casemapping functions.
------------------------------------------------------------------------
[2018-05-09 19:00:36] nikic@php.net
<?php
var_dump(mb_strtolower("a\xA1\x0B", 'UTF-8'));
UTF-8 is the default encoding and \xA1\x0B is invalid UTF-8. Clearly something is going wrong with
handling invalid UTF-8.
------------------------------------------------------------------------
[2018-05-09 18:50:42] ion dot bazan at gmail dot com
Calling:
mb_strtolower(urldecode('a%A1%C0b'), 'ASCII')
works properly though.
------------------------------------------------------------------------
[2018-05-09 18:46:36] ion dot bazan at gmail dot com
Change category
------------------------------------------------------------------------
[2018-05-09 18:44:25] ion dot bazan at gmail dot com
Description:
------------
Calling mb_strtolower without specifying the encoding may cause unexpected buffer overflow while on
PHP 7.2 it works properly.
Test script:
---------------
var_dump(mb_strtolower(urldecode('a%A1%C0b')));
Expected result:
----------------
string(4) "a??b"
Actual result:
--------------
*** buffer overflow detected ***: php terminated
======= Backtrace: =========
/lib/x86_64-linux-gnu/libc.so.6(+0x7329f)[0x7f3bc3f2f29f]
/lib/x86_64-linux-gnu/libc.so.6(__fortify_fail+0x5c)[0x7f3bc3fca83c]
/lib/x86_64-linux-gnu/libc.so.6(+0x10d710)[0x7f3bc3fc9710]
php[0x6f8f6d]
php[0x6e8031]
php(php_unicode_convert_case+0xbd)[0x6f917d]
php[0x6f26c3]
php(execute_ex+0x8e25)[0x9d15e5]
php(zend_call_function+0x7de)[0x92533e]
php[0x76fdba]
php(execute_ex+0x8e25)[0x9d15e5]
php(zend_execute+0x1d6)[0x9d26c6]
php(zend_execute_scripts+0xe7)[0x9366f7]
php(php_execute_script+0x3a6)[0x8c7116]
php[0x9d4cda]
php[0x45e8d0]
--- CUT ---
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=76319&edit=1