Edit report at https://bugs.php.net/bug.php?id=79225&edit=1
ID: 79225
Updated by: nikic@php.net
Reported by: geeknik at protonmail dot ch
Summary: Risk of integer overflow in logical_filters.c
-Status: Open
+Status: Not a bug
-Type: Security
+Type: Bug
Package: Filter related
Operating System: Ubuntu
PHP Version: 7.4Git-2020-02-04 (Git)
Block user comment: N
Private report: Y
New Comment:
That's correct, there can be no overflow here.
Previous Comments:
------------------------------------------------------------------------
[2020-02-04 17:56:48] cmb@php.net
> It may be possible to overflow this 'int' [â¦]
How so? It seems to me that the right-hand factor of the
multiplication[1] evaluates to 1..9.
[1] <https://github.com/php/php-src/blob/php-7.4.3RC1/ext/filter/logical_filters.c#L117>
------------------------------------------------------------------------
[2020-02-04 14:44:16] geeknik at protonmail dot ch
Description:
------------
Line 117 of logical_filters.c looks like so:
ctx_value = ((sign)?-1:1) * ((*(str++)) - '0');
It may be possible to overflow this 'int' before it is converted to 'zend_long'.
Please tell me what you think.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=79225&edit=1