Edit report at https://bugs.php.net/bug.php?id=75934&edit=1
ID: 75934
Updated by: cmb@php.net
Reported by: zhihua dot yao at dbappsecurity dot com dot cn
Summary: Out of Bound in sodium_pad
Status: Assigned
Type: Bug
Package: Reproducible crash
PHP Version: 7.2.2
Assigned To: jedisct1
Block user comment: N
Private report: N
New Comment:
@jedisct1, please see the closely related PR #7252[1], especially
Dmitry's comment near the end, and the follow up solution PR
#7294[2].
TL;DR: use ZSTR_MAX_LEN instead of SIZE_MAX.
[1] <https://github.com/php/php-src/pull/7252>
[2] <https://github.com/php/php-src/pull/7294>
Previous Comments:
------------------------------------------------------------------------
[2018-04-30 06:23:38] zhihua dot yao at dbappsecurity dot com dot cn
Yes, @spam2.rhsoft.net,In the past, this should be classified as a security issue
------------------------------------------------------------------------
[2018-04-29 18:23:10] spam2 at rhsoft dot net
https://wiki.php.net/security
We do not classify as a security issue any issue that:
requires invocation of specific code, which may be valid but is obviously malicious
requires invocation of functions with specific arguments, which may be valid but are obviously
malicious
requires specific actions to be performed on the server, which are not commonly performed, or are
not commonly permissible for the user (uid) executing PHP
requires privileges superior to that of the user (uid) executing PHP
requires the use of debugging facilities - ex. xdebug, var_dump
requires the use of settings not recommended for production - ex. error reporting to output
requires the use of non-standard environment variables - ex. USE_ZEND_ALLOC
requires the use of non-standard builds - ex. obscure embedded platform, not commonly used compiler
requires the use of code or settings known to be insecure
------------------------------------------------------------------------
[2018-04-29 17:36:23] spam2 at rhsoft dot net
sadly the php-developers typically don't consider something which needs to be triggered with
code like yours or whatever triggers a OOM as security issue
there are many bug reports in the recent past "just verify your input" classified
------------------------------------------------------------------------
[2018-04-29 17:33:23] jedisct1@php.net
This can be downplayed by pointing out the fact that
ini_set('memory_limit',-1); is not a thing to allow on untrusted
data/scripts.
But altering the memory_limit value may not be required to trigger this overflow.
------------------------------------------------------------------------
[2018-04-29 17:30:18] jedisct1@php.net
I'd consider this a security issue. Which is trivial to trigger:
ini_set('memory_limit',-1);
$a = str_repeat('x', 2147483647);
$b = $a . $a;
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=75934
--
Edit this bug report at https://bugs.php.net/bug.php?id=75934&edit=1