Bug #77322 [PATCH]: PharData::addEmptyDir('/') Possible integer overflow

From: Date: Fri, 11 Dec 2020 15:58:13 +0000
Subject: Bug #77322 [PATCH]: PharData::addEmptyDir('/') Possible integer overflow
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-231028@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77322&edit=1 ID: 77322 Patch added by: cmb@php.net Reported by: lars at larsegon dot se Summary: PharData::addEmptyDir('/') Possible integer overflow Status: Verified Type: Bug Package: PHAR related Operating System: Linux PHP Version: 7.1.25 Assigned To: cmb Block user comment: N Private report: N New Comment: The following pull request has been associated: Patch Name: Fix #77322: PharData::addEmptyDir('/') Possible integer overflow On GitHub: https://github.com/php/php-src/pull/6508 Patch: https://github.com/php/php-src/pull/6508.patch Previous Comments: ------------------------------------------------------------------------ [2018-12-20 10:21:59] lars at larsegon dot se Description: ------------ When trying to add the empty directory '/' to a phar archive PHP throws a fatal error: PHP Fatal error: Possible integer overflow in memory allocation (1 * 18446744073709551615 + 1) in /path/to/my/script.php on line 91 The same action works in ZipArchive, i.e. this works: $zip = new \ZipArchive; $zip->open(tempnam(sys_get_temp_dir(), "phptest")); $zip->addEmptyDir("/"); Test script: --------------- $tar = new \PharData("/tmp/phptempfile"); $tar->addEmptyDir("/"); // Fatal error Possible Integer overflow ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=77322&edit=1

« previous php.bugs (#231028) next »