Bug #75934 [Asn]: Out of Bound in sodium_pad

From: Date: Wed, 21 Jul 2021 13:41:29 +0000
Subject: Bug #75934 [Asn]: Out of Bound in sodium_pad
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-235236@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=75934&edit=1

 ID:                 75934
 Updated by:         cmb@php.net
 Reported by:        zhihua dot yao at dbappsecurity dot com dot cn
 Summary:            Out of Bound in sodium_pad
 Status:             Assigned
 Type:               Bug
 Package:            Reproducible crash
 PHP Version:        7.2.2
 Assigned To:        jedisct1
 Block user comment: N
 Private report:     N

 New Comment:

@jedisct1, please see the closely related PR #7252[1], especially
Dmitry's comment near the end, and the follow up solution PR
#7294[2].

TL;DR: use ZSTR_MAX_LEN instead of SIZE_MAX.

[1] <https://github.com/php/php-src/pull/7252>
[2] <https://github.com/php/php-src/pull/7294>


Previous Comments:
------------------------------------------------------------------------
[2018-04-30 06:23:38] zhihua dot yao at dbappsecurity dot com dot cn

Yes, @spam2.rhsoft.net,In the past, this should be classified as a security issue

------------------------------------------------------------------------
[2018-04-29 18:23:10] spam2 at rhsoft dot net

https://wiki.php.net/security

We do not classify as a security issue any issue that:

requires invocation of specific code, which may be valid but is obviously malicious

requires invocation of functions with specific arguments, which may be valid but are obviously
malicious

requires specific actions to be performed on the server, which are not commonly performed, or are
not commonly permissible for the user (uid) executing PHP

requires privileges superior to that of the user (uid) executing PHP

requires the use of debugging facilities - ex. xdebug, var_dump

requires the use of settings not recommended for production - ex. error reporting to output

requires the use of non-standard environment variables - ex. USE_ZEND_ALLOC

requires the use of non-standard builds - ex. obscure embedded platform, not commonly used compiler

requires the use of code or settings known to be insecure

------------------------------------------------------------------------
[2018-04-29 17:36:23] spam2 at rhsoft dot net

sadly the php-developers typically don't consider something which needs to be triggered with
code like yours or whatever triggers a OOM as security issue

there are many bug reports in the recent past "just verify your input" classified

------------------------------------------------------------------------
[2018-04-29 17:33:23] jedisct1@php.net

This can be downplayed by pointing out the fact that
ini_set('memory_limit',-1); is not a thing to allow on untrusted
data/scripts. 

But altering the memory_limit value may not be required to trigger this overflow.

------------------------------------------------------------------------
[2018-04-29 17:30:18] jedisct1@php.net

I'd consider this a security issue. Which is trivial to trigger:

ini_set('memory_limit',-1);
$a = str_repeat('x', 2147483647);
$b = $a . $a;

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=75934


--
Edit this bug report at https://bugs.php.net/bug.php?id=75934&edit=1


Thread (16 messages)

« previous php.bugs (#235236) next »