Bug #73246 [Asn->Csd]: XMLReader: encoding length not checked
| From: | git@php.net | Date: | Mon, 03 May 2021 10:31:31 +0000 |
| Subject: | Bug #73246 [Asn->Csd]: XMLReader: encoding length not checked | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-233635@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=73246&edit=1
ID: 73246
Updated by: git@php.net
Reported by: fernando at null-life dot com
Summary: XMLReader: encoding length not checked
-Status: Assigned
+Status: Closed
Type: Bug
Package: XML Reader
Operating System: Linux x64
PHP Version: 7.0.11
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of cmb69
Revision: https://github.com/php/php-src/commit/272df442f5a9617bf19e55ba5c6e3180315a18cf
Log: Fix #73246: XMLReader: encoding length not checked
Previous Comments:
------------------------------------------------------------------------
[2021-04-22 09:49:10] cmb@php.net
The following pull request has been associated:
Patch Name: Fix #73246: XMLReader: encoding length not checked
On GitHub: https://github.com/php/php-src/pull/6899
Patch: https://github.com/php/php-src/pull/6899.patch
------------------------------------------------------------------------
[2021-04-21 18:16:59] stas@php.net
The null thing doesn't look like security issue. The other thing doesn't look like PHP
issue. Let's fix the null thing in 7.4+.
------------------------------------------------------------------------
[2021-04-21 13:27:02] cmb@php.net
More appropriate patch for PHP-7.4:
<https://gist.github.com/cmb69/6f8720154c016bfceeee72c400870b48>.
IMO, not a security issue.
------------------------------------------------------------------------
[2020-03-18 12:58:45] cmb@php.net
The reported stack overflow is certainly not a PHP bug.
> encoding length not checked
This is a bug, but I'm not sure whether it is a security issue.
stas, what do you think?
Anyway, fix would be as simple as:
ext/xmlreader/php_xmlreader.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/ext/xmlreader/php_xmlreader.c b/ext/xmlreader/php_xmlreader.c
index 4d4e7348c9..f920d04eb7 100644
--- a/ext/xmlreader/php_xmlreader.c
+++ b/ext/xmlreader/php_xmlreader.c
@@ -848,7 +848,7 @@ PHP_METHOD(xmlreader, open)
char resolved_path[MAXPATHLEN + 1];
xmlTextReaderPtr reader = NULL;
- if (zend_parse_parameters(ZEND_NUM_ARGS(), "p|s!l", &source, &source_len,
&encoding, &encoding_len, &options) == FAILURE) {
+ if (zend_parse_parameters(ZEND_NUM_ARGS(), "p|p!l", &source, &source_len,
&encoding, &encoding_len, &options) == FAILURE) {
return;
}
@@ -1033,7 +1033,7 @@ PHP_METHOD(xmlreader, XML)
xmlParserInputBufferPtr inputbfr;
xmlTextReaderPtr reader;
- if (zend_parse_parameters(ZEND_NUM_ARGS(), "s|s!l", &source, &source_len,
&encoding, &encoding_len, &options) == FAILURE) {
+ if (zend_parse_parameters(ZEND_NUM_ARGS(), "s|p!l", &source, &source_len,
&encoding, &encoding_len, &options) == FAILURE) {
return;
}
------------------------------------------------------------------------
[2017-10-17 14:40:17] cmb@php.net
iconv_open() is supposed to accept two const char * without any particular
restrictions on their length. So, this looks like a bug in the iconv_open()
implementation.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=73246
--
Edit this bug report at https://bugs.php.net/bug.php?id=73246&edit=1