Bug #67619 [Ver->Csd]: Length parameters in socket_write() etc. may be negative
Edit report at https://bugs.php.net/bug.php?id=67619&edit=1
ID: 67619
Updated by: cmb@php.net
Reported by: tstarling@php.net
Summary: Length parameters in socket_write() etc. may be
negative
-Status: Verified
+Status: Closed
Type: Bug
Package: Sockets related
Operating System: Linux
PHP Version: 7.2.4
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Fixed as of PHP 7.1.25 and 7.2.13, repectively.
Previous Comments:
------------------------------------------------------------------------
[2014-07-14 22:54:27] tstarling@php.net
Description:
------------
In socket_write(), socket_send() and socket_sendto(), it is not checked whether the length parameter
is negative. If it is negative, it will be converted to a size_t for the underlying syscall, so a
write of more than 2GB will be requested. In my testing, this fails with EFAULT. It is conceivable
that it may instead be a buffer overflow on some embedded systems.
I suggest validating the length parameter.
Test script:
---------------
$f = socket_create(AF_INET, SOCK_STREAM, SOL_TCP);
socket_connect($f, '127.0.0.1',8888);
socket_write($f, "Hello\n", -1);
Actual result:
--------------
Warning: socket_write(): unable to write to socket [14]: Bad address
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=67619&edit=1
Thread (3 messages)