Sec Bug->Bug #77962 [Opn]: finfo_open crafted magic parsing SIGFPE

From: Date: Mon, 06 May 2019 00:40:00 +0000
Subject: Sec Bug->Bug #77962 [Opn]: finfo_open crafted magic parsing SIGFPE
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-220712@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77962&edit=1 ID: 77962 Updated by: stas@php.net Reported by: radimre83 at gmail dot com Summary: finfo_open crafted magic parsing SIGFPE Status: Open -Type: Security +Type: Bug Package: Filesystem function related Operating System: Linux PHP Version: 7.3.5 Block user comment: N Private report: Y New Comment: Please do not reclassify this bug again. If in doubt, please read https://wiki.php.net/security Previous Comments: ------------------------------------------------------------------------ [2019-05-05 17:37:55] radimre83 at gmail dot com Ah sorry, I didnt notice the comments (did not receive any email notifications about them...), and now I cannot revert it back to Bug. ------------------------------------------------------------------------ [2019-05-05 17:35:39] radimre83 at gmail dot com Changing bug type to security. ------------------------------------------------------------------------ [2019-05-02 20:16:38] ab@php.net Hi, thanks for the report. If garbage or incompatible data was passed to libmagic, any kinds of issues are just expected. PHP supplies the curated magic data which guarantees compatibility. Otherwise it's user responsibility, if external file is needed. So it is for sure not a security issue. Furthermore, crash just reflects what happens in libmagic. This is the way how libmagic works and similar behaviors has been sighted in previous versions. I'd suggest to go upstream first, then we could land a patch if suitable. Thanks. ------------------------------------------------------------------------ [2019-05-02 17:30:29] radimre83 at gmail dot com The bug tracker did not let me attaching the patch file this time. Pasting here as a simple text. Let me know if you have problem with reproducing the division by zero issue. 0 string 1 >1 regex \^[0-9:,\ ]*-->[0-9:,\ ]* SubRip File !:mime text/x-srt 0 lelong 0xc3cbc6c5 RISC OS Chunk data >12 string OBJ_ \b, AOF object >12 string LIB_ \b, ALF library 0 name mach-o \b [ >0 use mach-o-cpu \b >(8.L) indirect x \b: >0 belong x \b] 0 belong 0xcafed00d JAR compressed with pack200, >5 byte x version %d. >4 byte x \b%d !:mime application/x-java-pack200 # Objective-C 0 regex \^#import Objective-C source text !:strength + 25 !:mime text/x-objective-c 0 string \x20\x20\x20\x20\x20\x20\x20\x20-:\x20\x20\x20\ 0:Source: >&0 search/128 \x20\x20\x20\x20\x20\x20\x20\x20-:\x20\x20\x20\ 0:Graph: >>&0 search/128 \x20\x20\x20\x20\x20\x20\x20\x20-:\x20\x20\x20\ 0:Data: GCOV coverage >>report 0 name certinfo >0 der seq >>&0 der set >>>&0 der seq >>>>&0 der obj_id3=550406 >>>>&0 der prt_str=x \b, countryName=%s >>&0 der set >>>&0 der seq >>>>&0 der obj_id3=550408 >>>>&0 der utf8_str=x \b, stateOrProvinceName=%s >>&0 der set >>>&0 der seq >>>>&0 der obj_id3=55040a >>>>&0 der utf8_str=x \b, organizationName=%s >>&0 der set >>>&0 der seq >>>>&0 der obj_id3=550403 >>>>&0 der utf8_str=x \b, commonName=%s >>&0 der seq 0 search ------------------------------------------------------------------------ [2019-05-02 17:30:02] stas@php.net I don't think using user-supplied magic database is a common scenario for PHP users. So doesn't look like a security issue. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=77962 -- Edit this bug report at https://bugs.php.net/bug.php?id=77962&edit=1

« previous php.bugs (#220712) next »