Bug #73246 [Asn->Csd]: XMLReader: encoding length not checked

From: Date: Mon, 03 May 2021 10:31:31 +0000
Subject: Bug #73246 [Asn->Csd]: XMLReader: encoding length not checked
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-233635@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73246&edit=1 ID: 73246 Updated by: git@php.net Reported by: fernando at null-life dot com Summary: XMLReader: encoding length not checked -Status: Assigned +Status: Closed Type: Bug Package: XML Reader Operating System: Linux x64 PHP Version: 7.0.11 Assigned To: cmb Block user comment: N Private report: N New Comment: Automatic comment on behalf of cmb69 Revision: https://github.com/php/php-src/commit/272df442f5a9617bf19e55ba5c6e3180315a18cf Log: Fix #73246: XMLReader: encoding length not checked Previous Comments: ------------------------------------------------------------------------ [2021-04-22 09:49:10] cmb@php.net The following pull request has been associated: Patch Name: Fix #73246: XMLReader: encoding length not checked On GitHub: https://github.com/php/php-src/pull/6899 Patch: https://github.com/php/php-src/pull/6899.patch ------------------------------------------------------------------------ [2021-04-21 18:16:59] stas@php.net The null thing doesn't look like security issue. The other thing doesn't look like PHP issue. Let's fix the null thing in 7.4+. ------------------------------------------------------------------------ [2021-04-21 13:27:02] cmb@php.net More appropriate patch for PHP-7.4: <https://gist.github.com/cmb69/6f8720154c016bfceeee72c400870b48>. IMO, not a security issue. ------------------------------------------------------------------------ [2020-03-18 12:58:45] cmb@php.net The reported stack overflow is certainly not a PHP bug. > encoding length not checked This is a bug, but I'm not sure whether it is a security issue. stas, what do you think? Anyway, fix would be as simple as: ext/xmlreader/php_xmlreader.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/ext/xmlreader/php_xmlreader.c b/ext/xmlreader/php_xmlreader.c index 4d4e7348c9..f920d04eb7 100644 --- a/ext/xmlreader/php_xmlreader.c +++ b/ext/xmlreader/php_xmlreader.c @@ -848,7 +848,7 @@ PHP_METHOD(xmlreader, open) char resolved_path[MAXPATHLEN + 1]; xmlTextReaderPtr reader = NULL; - if (zend_parse_parameters(ZEND_NUM_ARGS(), "p|s!l", &source, &source_len, &encoding, &encoding_len, &options) == FAILURE) { + if (zend_parse_parameters(ZEND_NUM_ARGS(), "p|p!l", &source, &source_len, &encoding, &encoding_len, &options) == FAILURE) { return; } @@ -1033,7 +1033,7 @@ PHP_METHOD(xmlreader, XML) xmlParserInputBufferPtr inputbfr; xmlTextReaderPtr reader; - if (zend_parse_parameters(ZEND_NUM_ARGS(), "s|s!l", &source, &source_len, &encoding, &encoding_len, &options) == FAILURE) { + if (zend_parse_parameters(ZEND_NUM_ARGS(), "s|p!l", &source, &source_len, &encoding, &encoding_len, &options) == FAILURE) { return; } ------------------------------------------------------------------------ [2017-10-17 14:40:17] cmb@php.net iconv_open() is supposed to accept two const char * without any particular restrictions on their length. So, this looks like a bug in the iconv_open() implementation. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=73246 -- Edit this bug report at https://bugs.php.net/bug.php?id=73246&edit=1

« previous php.bugs (#233635) next »