Bug #79149 [Asn->Csd]: SEGV in mb_convert_encoding with non-string encodings

From: Date: Wed, 22 Jan 2020 08:46:22 +0000
Subject: Bug #79149 [Asn->Csd]: SEGV in mb_convert_encoding with non-string encodings
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-225041@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=79149&edit=1 ID: 79149 Updated by: cmb@php.net Reported by: wxhusst at gmail dot com Summary: SEGV in mb_convert_encoding with non-string encodings -Status: Assigned +Status: Closed Type: Bug Package: mbstring related Operating System: linux PHP Version: PHP 7.4 Assigned To: cmb Block user comment: N Private report: N New Comment: Automatic comment on behalf of cmbecker69@gmx.de Revision: http://git.php.net/?p=php-src.git;a=commit;h=94c9dc498ffdedd9ae91357bd3345ba31f232220 Log: Fix #79149: SEGV in mb_convert_encoding with non-string encodings Previous Comments: ------------------------------------------------------------------------ [2020-01-22 08:45:12] cmb@php.net Thanks for checking Nikita! To clarify, PHP 7.3 and earlier are not affected by this issue. ------------------------------------------------------------------------ [2020-01-22 08:34:41] cmb@php.net Related To: Bug #79150 ------------------------------------------------------------------------ [2020-01-21 17:54:05] nikic@php.net Patch LGTM. ------------------------------------------------------------------------ [2020-01-21 17:16:49] cmb@php.net Suggested fix for PHP 7.4: <https://gist.github.com/cmb69/080acb60a50d40f76bc7b628b376b5e4>. For PHP 7.3 we should also replace the convert_to_string_ex()[1], which can modify passed arguments. Regarding exploitability: mb_convert_encoding($_GET['text'], 'UTF-8', $_GET['encodings']) would be vulnerable. However, that would be a userland bug, in my opionion. [1] <https://github.com/php/php-src/blob/php-7.3.14/ext/mbstring/mbstring.c#L3236> ------------------------------------------------------------------------ [2020-01-21 16:55:05] wxhusst at gmail dot com I also think this don't seem like a realistic pathway for remote exploitation, :) ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=79149 -- Edit this bug report at https://bugs.php.net/bug.php?id=79149&edit=1

« previous php.bugs (#225041) next »