Bug #79149 [Asn->Csd]: SEGV in mb_convert_encoding with non-string encodings
| From: | cmb@php.net | Date: | Wed, 22 Jan 2020 08:46:22 +0000 |
| Subject: | Bug #79149 [Asn->Csd]: SEGV in mb_convert_encoding with non-string encodings | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-225041@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=79149&edit=1
ID: 79149
Updated by: cmb@php.net
Reported by: wxhusst at gmail dot com
Summary: SEGV in mb_convert_encoding with non-string
encodings
-Status: Assigned
+Status: Closed
Type: Bug
Package: mbstring related
Operating System: linux
PHP Version: PHP 7.4
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of cmbecker69@gmx.de
Revision: http://git.php.net/?p=php-src.git;a=commit;h=94c9dc498ffdedd9ae91357bd3345ba31f232220
Log: Fix #79149: SEGV in mb_convert_encoding with non-string encodings
Previous Comments:
------------------------------------------------------------------------
[2020-01-22 08:45:12] cmb@php.net
Thanks for checking Nikita!
To clarify, PHP 7.3 and earlier are not affected by this issue.
------------------------------------------------------------------------
[2020-01-22 08:34:41] cmb@php.net
Related To: Bug #79150
------------------------------------------------------------------------
[2020-01-21 17:54:05] nikic@php.net
Patch LGTM.
------------------------------------------------------------------------
[2020-01-21 17:16:49] cmb@php.net
Suggested fix for PHP 7.4:
<https://gist.github.com/cmb69/080acb60a50d40f76bc7b628b376b5e4>.
For PHP 7.3 we should also replace the convert_to_string_ex()[1],
which can modify passed arguments.
Regarding exploitability:
mb_convert_encoding($_GET['text'], 'UTF-8', $_GET['encodings'])
would be vulnerable. However, that would be a userland bug, in my
opionion.
[1] <https://github.com/php/php-src/blob/php-7.3.14/ext/mbstring/mbstring.c#L3236>
------------------------------------------------------------------------
[2020-01-21 16:55:05] wxhusst at gmail dot com
I also think this don't seem like a realistic pathway for remote exploitation, :)
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=79149
--
Edit this bug report at https://bugs.php.net/bug.php?id=79149&edit=1