Sec Bug->Bug #79225 [Opn->Nab]: Risk of integer overflow in logical_filters.c

From: Date: Wed, 05 Feb 2020 17:00:03 +0000
Subject: Sec Bug->Bug #79225 [Opn->Nab]: Risk of integer overflow in logical_filters.c
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-225377@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=79225&edit=1

 ID:                 79225
 Updated by:         nikic@php.net
 Reported by:        geeknik at protonmail dot ch
 Summary:            Risk of integer overflow in logical_filters.c
-Status:             Open
+Status:             Not a bug
-Type:               Security
+Type:               Bug
 Package:            Filter related
 Operating System:   Ubuntu
 PHP Version:        7.4Git-2020-02-04 (Git)
 Block user comment: N
 Private report:     Y

 New Comment:

That's correct, there can be no overflow here.


Previous Comments:
------------------------------------------------------------------------
[2020-02-04 17:56:48] cmb@php.net

> It may be possible to overflow this 'int' […]

How so?  It seems to me that the right-hand factor of the
multiplication[1] evaluates to 1..9.

[1] <https://github.com/php/php-src/blob/php-7.4.3RC1/ext/filter/logical_filters.c#L117>

------------------------------------------------------------------------
[2020-02-04 14:44:16] geeknik at protonmail dot ch

Description:
------------
Line 117 of logical_filters.c looks like so:

ctx_value = ((sign)?-1:1) * ((*(str++)) - '0');

It may be possible to overflow this 'int' before it is converted to 'zend_long'.
Please tell me what you think.



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=79225&edit=1


Thread (1 message)

  • nikic@php.net
  • Unknown Message
    • nikic@php.net
« previous php.bugs (#225377) next »