Bug #68690 [Opn]: Hypothetical off-by-one loop termination

From: Date: Fri, 03 Apr 2020 12:07:04 +0000
Subject: Bug #68690 [Opn]: Hypothetical off-by-one loop termination
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-226424@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68690&edit=1 ID: 68690 Updated by: cmb@php.net Reported by: bugreports at internot dot info -Summary: Off-by-one out-of-bounds write +Summary: Hypothetical off-by-one loop termination Status: Open Type: Bug Package: mbstring related Operating System: Linux Ubuntu 14.04 PHP Version: master-Git-2014-12-30 (Git) -Assigned To: +Assigned To: cmb Block user comment: N Private report: N New Comment: > This implies that filter->cache can be between (inclusive) 0-25. It seems to me filter->cache == 25 cannot happen, since the check for the first character of a combining character immediately above gets the loop termination right. Still, the code is confusing. > 'k' may be up to '5', which overruns it, I believe. No, that can't happen, because the code can only be reached if the character is_in_cp950_pua(), and if it is, the loop always breaks. Previous Comments: ------------------------------------------------------------------------ [2014-12-30 04:13:19] bugreports at internot dot info Same code as above comment in the same file: L195-201. Thanks, ------------------------------------------------------------------------ [2014-12-30 04:09:02] bugreports at internot dot info There is also questionable code in /ext/mbstring/libmbfl/filters/mbfilter_big5.c: 262 for (k = 0; k < sizeof(cp950_pua_tbl)/(sizeof(unsigned short)*4); k++) { 263 if (c <= cp950_pua_tbl[k][1]) { 264 break; 265 } 266 } 267 c1 = c - cp950_pua_tbl[k][0]; ^^ 'k' may be up to '5', which overruns it, I believe. Thanks, ------------------------------------------------------------------------ [2014-12-30 04:05:18] bugreports at internot dot info Description: ------------ Hi, In /ext/mbstring/libmbfl/filters/mbfilter_sjis_2004.c: 508 if ((filter->status & 0xf) == 1 && 509 filter->cache >= 0 && filter->cache <= jisx0213_u2_tbl_len) { This implies that filter->cache can be between (inclusive) 0-25. Then: 514 c1 = jisx0213_u2_tbl[2*k]; If k is 25, it will evaluate to 50. It also may occur here: 519 if (c == jisx0213_u2_tbl[2*k+1]) { Thanks, ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=68690&edit=1

« previous php.bugs (#226424) next »