Sec Bug->Bug #79150 [Ver->Dup]: memcpy-param-overlap caused by zif_mb_convert_encoding

From: Date: Wed, 22 Jan 2020 08:34:41 +0000
Subject: Sec Bug->Bug #79150 [Ver->Dup]: memcpy-param-overlap caused by zif_mb_convert_encoding
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-225039@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=79150&edit=1 ID: 79150 Updated by: cmb@php.net Reported by: wxhusst at gmail dot com Summary: memcpy-param-overlap caused by zif_mb_convert_encoding -Status: Verified +Status: Duplicate -Type: Security +Type: Bug Package: mbstring related Operating System: linux PHP Version: 7.4Git-2020-01-21 (Git) Assigned To: cmb Block user comment: N Private report: Y New Comment: This is actually a duplicate of bug #79149. Previous Comments: ------------------------------------------------------------------------ [2020-01-21 16:30:56] cmb@php.net Related To: Bug #79149 ------------------------------------------------------------------------ [2020-01-21 16:23:41] cmb@php.net Thanks for reporting! ------------------------------------------------------------------------ [2020-01-21 14:33:39] wxhusst at gmail dot com Description: ------------ ==119497==ERROR: AddressSanitizer: memcpy-param-overlap: memory ranges [0x7f29aaa02052,0xfe535547e2db) and [0x7f29aaa59c78, 0xfe53554d5f01) overlap #0 0x6acd38 in __asan_memcpy /home/buildnode/jenkins/workspace/oss-swift-5.1-package-linux-ubuntu-18_04/llvm/projects/compiler-rt/lib/asan/asan_interceptors_memintrinsics.cc:23:3 #1 0x10c0f2c in zif_mb_convert_encoding /home/raven/fuzz/php-src-php-7.4.2/ext/mbstring/mbstring.c:3375:7 #2 0x242215d in ZEND_DO_ICALL_SPEC_RETVAL_UNUSED_HANDLER /home/raven/fuzz/php-src-php-7.4.2/Zend/zend_vm_execute.h:1269:2 #3 0x2131c97 in execute_ex /home/raven/fuzz/php-src-php-7.4.2/Zend/zend_vm_execute.h:53611:7 #4 0x2132d52 in zend_execute /home/raven/fuzz/php-src-php-7.4.2/Zend/zend_vm_execute.h:57913:2 #5 0x1eb6d8c in zend_execute_scripts /home/raven/fuzz/php-src-php-7.4.2/Zend/zend.c:1665:4 #6 0x1a9b754 in php_execute_script /home/raven/fuzz/php-src-php-7.4.2/main/main.c:2617:14 #7 0x255f9f0 in do_cli /home/raven/fuzz/php-src-php-7.4.2/sapi/cli/php_cli.c:961:5 #8 0x255c3a7 in main /home/raven/fuzz/php-src-php-7.4.2/sapi/cli/php_cli.c:1352:18 #9 0x7f29b00c41e2 in __libc_start_main /build/glibc-4WA41p/glibc-2.30/csu/../csu/libc-start.c:308:16 #10 0x602b3d in _start (/home/raven/fuzz/php-src-php-7.4.2/sapi/cli/php+0x602b3d) Address 0x7f29aaa02052 is a wild pointer. Address 0x7f29aaa59c78 is a wild pointer. SUMMARY: AddressSanitizer: memcpy-param-overlap /home/buildnode/jenkins/workspace/oss-swift-5.1-package-linux-ubuntu-18_04/llvm/projects/compiler-rt/lib/asan/asan_interceptors_memintrinsics.cc:23:3 in __asan_memcpy ==119497==ABORTING Test script: --------------- <?php try { try { mb_convert_encoding(range(0, 10), str_repeat(chr(193), 65537) + str_repeat(chr(168), 65), array(array("Volvo",100,96),range(0,10),array("a" => 1, "b" => "2", "c" => 3.0))); } catch (Exception $e) { } } catch(Error $e) { } ?> Expected result: ---------------- normal Actual result: -------------- crash ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=79150&edit=1

« previous php.bugs (#225039) next »