Bug #77484 [Com]: Zend engine crashes when calling realpath in invalid working dir

From: Date: Fri, 18 Jan 2019 23:32:16 +0000
Subject: Bug #77484 [Com]: Zend engine crashes when calling realpath in invalid working dir
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-219074@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77484&edit=1 ID: 77484 Comment by: spam2 at rhsoft dot net Reported by: marcospassos dot com at gmail dot com Summary: Zend engine crashes when calling realpath in invalid working dir Status: Verified Type: Bug Package: *Directory/Filesystem functions Operating System: Mac OS 10.12.6 PHP Version: 7.3.1 Assigned To: ab Block user comment: N Private report: N New Comment: as said: outside the autistic php world it is considered as security bug as EVERY crash bug Previous Comments: ------------------------------------------------------------------------ [2019-01-18 20:03:16] stas@php.net Not a security issue - requires special condition and explicit user action to trigger. ------------------------------------------------------------------------ [2019-01-18 16:56:33] cmb@php.net There occurs an unsigned underflow in tsrm_realpath_r()[1]; the attached patch add-undeflow-check would solve this. Anatol, since you've refactored tsrm_realpath_r() to size_t, could you please review the patch? [1] <https://github.com/php/php-src/blob/php-7.3.1/Zend/zend_virtual_cwd.c#L767> ------------------------------------------------------------------------ [2019-01-18 16:56:30] cmb@php.net The following patch has been added/updated: Patch Name: add-undeflow-check Revision: 1547830590 URL: https://bugs.php.net/patch-display.php?bug=77484&patch=add-undeflow-check&revision=1547830590 ------------------------------------------------------------------------ [2019-01-18 11:31:57] cmb@php.net Tentatively marking as sec bug. ------------------------------------------------------------------------ [2019-01-18 00:31:47] spam2 at rhsoft dot net outside the PHP world this would classify as vulnerability when simple 2-liner crashs a shared server process ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=77484 -- Edit this bug report at https://bugs.php.net/bug.php?id=77484&edit=1

« previous php.bugs (#219074) next »