Bug #73763 [Opn->Dup]: phar header miscalculation
| From: | cmb@php.net | Date: | Wed, 04 Mar 2020 23:14:52 +0000 |
| Subject: | Bug #73763 [Opn->Dup]: phar header miscalculation | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-225888@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=73763&edit=1
ID: 73763
Updated by: cmb@php.net
Reported by: eyal dot itkin at gmail dot com
Summary: phar header miscalculation
-Status: Open
+Status: Duplicate
Type: Bug
Package: PHAR related
PHP Version: 7.1.0
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
This issue seems to have been fixed in the meantime[1], so I'm
closing as duplicate of bug #77143.
[1] <http://git.php.net/?p=php-src.git;a=commit;h=54212674b924aab506471060ff64986cda375f71>
Previous Comments:
------------------------------------------------------------------------
[2016-12-16 21:04:12] eyal dot itkin at gmail dot com
Description:
------------
phar_parse_pharfile() uses incorrect manifest header size of 10 bytes instead of 14 bytes. This
leads to several incorrect checks:
1) The constant should be 14 bytes, instead of 10:
if (manifest_len < 10 || manifest_len != php_stream_read(fp, buffer, manifest_len)) {
This means that later the alias length (tmp_len) is read without being checked to be present in the
buffer.
2) The alias length checks should be updated:
if (buffer + tmp_len > endbuffer) {
MAPPHAR_FAIL("internal corruption of phar \"%s\" (buffer overrun)");
}
if (manifest_len < 10 + tmp_len) {
MAPPHAR_FAIL("internal corruption of phar \"%s\" (truncated manifest header)")
}
1st check is vulnerable to integer-overflow, and the 2nd uses incorrect size and is redundant. Fix
should be:
if (tmp_len > endbuffer - buffer) {
MAPPHAR_FAIL("internal corruption of phar \"%s\" (buffer overrun)");
}
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=73763&edit=1