Sec Bug->Bug #77962 [Opn]: finfo_open crafted magic parsing SIGFPE
| From: | stas@php.net | Date: | Mon, 06 May 2019 00:40:00 +0000 |
| Subject: | Sec Bug->Bug #77962 [Opn]: finfo_open crafted magic parsing SIGFPE | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-220712@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77962&edit=1
ID: 77962
Updated by: stas@php.net
Reported by: radimre83 at gmail dot com
Summary: finfo_open crafted magic parsing SIGFPE
Status: Open
-Type: Security
+Type: Bug
Package: Filesystem function related
Operating System: Linux
PHP Version: 7.3.5
Block user comment: N
Private report: Y
New Comment:
Please do not reclassify this bug again. If in doubt, please read https://wiki.php.net/security
Previous Comments:
------------------------------------------------------------------------
[2019-05-05 17:37:55] radimre83 at gmail dot com
Ah sorry, I didnt notice the comments (did not receive any email notifications about them...), and
now I cannot revert it back to Bug.
------------------------------------------------------------------------
[2019-05-05 17:35:39] radimre83 at gmail dot com
Changing bug type to security.
------------------------------------------------------------------------
[2019-05-02 20:16:38] ab@php.net
Hi,
thanks for the report. If garbage or incompatible data was passed to libmagic, any kinds of issues
are just expected. PHP supplies the curated magic data which guarantees compatibility. Otherwise
it's user responsibility, if external file is needed. So it is for sure not a security issue.
Furthermore, crash just reflects what happens in libmagic. This is the way how libmagic works and
similar behaviors has been sighted in previous versions. I'd suggest to go upstream first, then
we could land a patch if suitable.
Thanks.
------------------------------------------------------------------------
[2019-05-02 17:30:29] radimre83 at gmail dot com
The bug tracker did not let me attaching the patch file this time. Pasting here as a simple text.
Let me know if you have problem with reproducing the division by zero issue.
0 string 1
>1 regex \^[0-9:,\ ]*-->[0-9:,\ ]* SubRip File
!:mime text/x-srt
0 lelong 0xc3cbc6c5 RISC OS Chunk data
>12 string OBJ_ \b, AOF object
>12 string LIB_ \b, ALF library
0 name mach-o \b [
>0 use mach-o-cpu \b
>(8.L) indirect x \b:
>0 belong x \b]
0 belong 0xcafed00d JAR compressed with pack200,
>5 byte x version %d.
>4 byte x \b%d
!:mime application/x-java-pack200
# Objective-C
0 regex \^#import Objective-C source text
!:strength + 25
!:mime text/x-objective-c
0 string \x20\x20\x20\x20\x20\x20\x20\x20-:\x20\x20\x20\ 0:Source:
>&0 search/128 \x20\x20\x20\x20\x20\x20\x20\x20-:\x20\x20\x20\ 0:Graph:
>>&0 search/128 \x20\x20\x20\x20\x20\x20\x20\x20-:\x20\x20\x20\ 0:Data: GCOV coverage
>>report
0 name certinfo
>0 der seq
>>&0 der set
>>>&0 der seq
>>>>&0 der obj_id3=550406
>>>>&0 der prt_str=x \b, countryName=%s
>>&0 der set
>>>&0 der seq
>>>>&0 der obj_id3=550408
>>>>&0 der utf8_str=x \b, stateOrProvinceName=%s
>>&0 der set
>>>&0 der seq
>>>>&0 der obj_id3=55040a
>>>>&0 der utf8_str=x \b, organizationName=%s
>>&0 der set
>>>&0 der seq
>>>>&0 der obj_id3=550403
>>>>&0 der utf8_str=x \b, commonName=%s
>>&0 der seq
0 search
------------------------------------------------------------------------
[2019-05-02 17:30:02] stas@php.net
I don't think using user-supplied magic database is a common scenario for PHP users. So
doesn't look like a security issue.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=77962
--
Edit this bug report at https://bugs.php.net/bug.php?id=77962&edit=1