Bug #75067 [Opn->Csd]: Passing of unterminated C string as argument to %s in format string
| From: | cmb@php.net | Date: | Fri, 15 Jan 2021 14:07:54 +0000 |
| Subject: | Bug #75067 [Opn->Csd]: Passing of unterminated C string as argument to %s in format string | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-231579@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=75067&edit=1
ID: 75067
Updated by: cmb@php.net
Reported by: enclaved at safe-mail dot net
Summary: Passing of unterminated C string as argument to %s
in format string
-Status: Open
+Status: Closed
Type: Bug
Package: Strings related
Operating System: All
PHP Version: 7.1.8
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
This has been fixed[1] in the meantime (available as of PHP
8.0.0). Regarding prior PHP versions, this is not really an
issue, since it would affect debug builds only, and it is not
supposed to happen anyway.
[1] <http://git.php.net/?p=php-src.git;a=commit;h=ef9ab9159b409c6d3ea184b4ba88764d85c4133b>
Previous Comments:
------------------------------------------------------------------------
[2017-08-12 17:33:00] enclaved at safe-mail dot net
Description:
------------
Zend/zend_API.h, around line 580:
#define CHECK_ZVAL_STRING(str) \
if (ZSTR_VAL(str)[ZSTR_LEN(str)] != '\0') { zend_error(E_WARNING, "String is not
zero-terminated (%s)", ZSTR_VAL(str)); }
#define CHECK_ZVAL_STRING_REL(str) \
if (ZSTR_VAL(str)[ZSTR_LEN(str)] != '\0') { zend_error(E_WARNING, "String is not
zero-terminated (%s) (source: %s:%d)", ZSTR_VAL(str) ZEND_FILE_LINE_RELAY_CC); }
Both of these macros pass unterminated C strings (as far as zend_string is concerned) to
zend_error() as arguments to the %s format string conversion specifier. Regardless of whether the
strings are implicitly terminated by whatever allocation method they use, this is generally a very
bad practice from the common C format string usage semantics. If a truly unterminated C string
wrapped in zend_string is passed to one of these macros, it will almost certainly result in delivery
of SIGBUS (or SIGSEGV on some platforms).
Please make a terminated copy of the string in question with estrndup() or similar means, giving
ZSTR_LEN() as an explicit length.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=75067&edit=1