Bug #68690 [Asn->Csd]: Hypothetical off-by-one condition
| From: | cmb@php.net | Date: | Fri, 03 Apr 2020 12:21:19 +0000 |
| Subject: | Bug #68690 [Asn->Csd]: Hypothetical off-by-one condition | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-226425@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=68690&edit=1
ID: 68690
Updated by: cmb@php.net
Reported by: bugreports at internot dot info
Summary: Hypothetical off-by-one condition
-Status: Assigned
+Status: Closed
Type: Bug
Package: mbstring related
Operating System: Linux Ubuntu 14.04
PHP Version: master-Git-2014-12-30 (Git)
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of cmbecker69@gmx.de
Revision: http://git.php.net/?p=php-src.git;a=commit;h=17d4e66204466cb5e3c0eb32aa18b8dbd9774ce3
Log: Fix #68690: Hypothetical off-by-one condition
Previous Comments:
------------------------------------------------------------------------
[2020-04-03 12:07:04] cmb@php.net
> This implies that filter->cache can be between (inclusive) 0-25.
It seems to me filter->cache == 25 cannot happen, since the check
for the first character of a combining character immediately above
gets the loop termination right. Still, the code is confusing.
> 'k' may be up to '5', which overruns it, I believe.
No, that can't happen, because the code can only be reached if the
character is_in_cp950_pua(), and if it is, the loop always breaks.
------------------------------------------------------------------------
[2014-12-30 04:13:19] bugreports at internot dot info
Same code as above comment in the same file:
L195-201.
Thanks,
------------------------------------------------------------------------
[2014-12-30 04:09:02] bugreports at internot dot info
There is also questionable code in /ext/mbstring/libmbfl/filters/mbfilter_big5.c:
262 for (k = 0; k < sizeof(cp950_pua_tbl)/(sizeof(unsigned short)*4); k++)
{
263 if (c <= cp950_pua_tbl[k][1]) {
264 break;
265 }
266 }
267 c1 = c - cp950_pua_tbl[k][0];
^^ 'k' may be up to '5', which overruns it, I believe.
Thanks,
------------------------------------------------------------------------
[2014-12-30 04:05:18] bugreports at internot dot info
Description:
------------
Hi,
In /ext/mbstring/libmbfl/filters/mbfilter_sjis_2004.c:
508 if ((filter->status & 0xf) == 1 &&
509 filter->cache >= 0 && filter->cache <= jisx0213_u2_tbl_len) {
This implies that filter->cache can be between (inclusive) 0-25.
Then:
514 c1 = jisx0213_u2_tbl[2*k];
If k is 25, it will evaluate to 50.
It also may occur here:
519 if (c == jisx0213_u2_tbl[2*k+1]) {
Thanks,
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=68690&edit=1