Bug #73763 [Opn->Dup]: phar header miscalculation

From: Date: Wed, 04 Mar 2020 23:14:52 +0000
Subject: Bug #73763 [Opn->Dup]: phar header miscalculation
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-225888@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73763&edit=1 ID: 73763 Updated by: cmb@php.net Reported by: eyal dot itkin at gmail dot com Summary: phar header miscalculation -Status: Open +Status: Duplicate Type: Bug Package: PHAR related PHP Version: 7.1.0 -Assigned To: +Assigned To: cmb Block user comment: N Private report: N New Comment: This issue seems to have been fixed in the meantime[1], so I'm closing as duplicate of bug #77143. [1] <http://git.php.net/?p=php-src.git;a=commit;h=54212674b924aab506471060ff64986cda375f71> Previous Comments: ------------------------------------------------------------------------ [2016-12-16 21:04:12] eyal dot itkin at gmail dot com Description: ------------ phar_parse_pharfile() uses incorrect manifest header size of 10 bytes instead of 14 bytes. This leads to several incorrect checks: 1) The constant should be 14 bytes, instead of 10: if (manifest_len < 10 || manifest_len != php_stream_read(fp, buffer, manifest_len)) { This means that later the alias length (tmp_len) is read without being checked to be present in the buffer. 2) The alias length checks should be updated: if (buffer + tmp_len > endbuffer) { MAPPHAR_FAIL("internal corruption of phar \"%s\" (buffer overrun)"); } if (manifest_len < 10 + tmp_len) { MAPPHAR_FAIL("internal corruption of phar \"%s\" (truncated manifest header)") } 1st check is vulnerable to integer-overflow, and the 2nd uses incorrect size and is redundant. Fix should be: if (tmp_len > endbuffer - buffer) { MAPPHAR_FAIL("internal corruption of phar \"%s\" (buffer overrun)"); } ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=73763&edit=1

« previous php.bugs (#225888) next »