Bug #77484 [Com]: Zend engine crashes when calling realpath in invalid working dir
| From: | spam2 at rhsoft dot net | Date: | Fri, 18 Jan 2019 23:32:16 +0000 |
| Subject: | Bug #77484 [Com]: Zend engine crashes when calling realpath in invalid working dir | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-219074@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77484&edit=1
ID: 77484
Comment by: spam2 at rhsoft dot net
Reported by: marcospassos dot com at gmail dot com
Summary: Zend engine crashes when calling realpath in invalid
working dir
Status: Verified
Type: Bug
Package: *Directory/Filesystem functions
Operating System: Mac OS 10.12.6
PHP Version: 7.3.1
Assigned To: ab
Block user comment: N
Private report: N
New Comment:
as said: outside the autistic php world it is considered as security bug as EVERY crash bug
Previous Comments:
------------------------------------------------------------------------
[2019-01-18 20:03:16] stas@php.net
Not a security issue - requires special condition and explicit user action to trigger.
------------------------------------------------------------------------
[2019-01-18 16:56:33] cmb@php.net
There occurs an unsigned underflow in tsrm_realpath_r()[1]; the
attached patch add-undeflow-check would solve this. Anatol, since
you've refactored tsrm_realpath_r() to size_t, could you please
review the patch?
[1] <https://github.com/php/php-src/blob/php-7.3.1/Zend/zend_virtual_cwd.c#L767>
------------------------------------------------------------------------
[2019-01-18 16:56:30] cmb@php.net
The following patch has been added/updated:
Patch Name: add-undeflow-check
Revision: 1547830590
URL: https://bugs.php.net/patch-display.php?bug=77484&patch=add-undeflow-check&revision=1547830590
------------------------------------------------------------------------
[2019-01-18 11:31:57] cmb@php.net
Tentatively marking as sec bug.
------------------------------------------------------------------------
[2019-01-18 00:31:47] spam2 at rhsoft dot net
outside the PHP world this would classify as vulnerability when simple 2-liner crashs a shared
server process
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=77484
--
Edit this bug report at https://bugs.php.net/bug.php?id=77484&edit=1