Bug #73122 [Csd->Ver]: Integer Overflow when concatenating strings

From: Date: Tue, 17 Aug 2021 14:07:43 +0000
Subject: Bug #73122 [Csd->Ver]: Integer Overflow when concatenating strings
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-235914@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73122&edit=1 ID: 73122 Updated by: cmb@php.net Reported by: tloi at fortinet dot com Summary: Integer Overflow when concatenating strings -Status: Closed +Status: Verified Type: Bug Package: Strings related PHP Version: master-Git-2016-09-20 (Git) -Assigned To: +Assigned To: cmb Block user comment: N Private report: N CVE-ID: 2017-8923 New Comment: This ticket has been closed accidentially. Note that this is not a security issue, so there shouldn't be a CVE. Since it obviously has already been assigned, I'm not sure what to do here. Previous Comments: ------------------------------------------------------------------------ [2021-08-17 14:00:53] git@php.net Automatic comment on behalf of cmb69 Revision: https://github.com/php/php-src/commit/f1ce8d5f5839cb2069ea37ff424fb96b8cd6932d Log: Fix #73122: Integer Overflow when concatenating strings ------------------------------------------------------------------------ [2018-03-02 18:52:36] contacto at agora-security dot com Has this issue been fixed? I don't see any reference about it in the Changelog: http://www.php.net/ChangeLog-7.php#7.1.5 ------------------------------------------------------------------------ [2017-05-12 06:46:14] requinix@php.net Related To: Bug #74577 ------------------------------------------------------------------------ [2016-09-20 10:06:34] tloi at fortinet dot com Description: ------------ Recently I notice php has been patched several times to prevent generating negative-length string to mitigate security issue. But the concat operation can still be used to overflow the length of string. PoC ran on 32 bit version This can be patched by checking len in either: ZEND_CONCAT_*() functions in Zend_vm_execute.h or zend_string_extend() function in Zend_string.h Test script: --------------- <?php ini_set('memory_limit', -1); $a = str_repeat('a',0x7fffffff)."aa"; print strlen($a); ?> Expected result: ---------------- zend_throw_error(NULL, "String size overflow"); Actual result: -------------- ➜ bin ./php -v PHP 7.2.0-dev (cli) (built: Sep 20 2016 16:41:04) ( NTS DEBUG ) Copyright (c) 1997-2016 The PHP Group Zend Engine v3.1.0-dev, Copyright (c) 1998-2016 Zend Technologies ➜ bin ./php poc.php -2147483647# =================== on another machine with php from ubuntu's official repository: root@ubuntu-4gb-sgp1-01:~# php -v PHP 7.0.8-0ubuntu0.16.04.2 (cli) ( NTS ) Copyright (c) 1997-2016 The PHP Group Zend Engine v3.0.0, Copyright (c) 1998-2016 Zend Technologies with Zend OPcache v7.0.8-0ubuntu0.16.04.2, Copyright (c) 1999-2016, by Zend Technologies root@ubuntu-4gb-sgp1-01:~# php poc.php mmap() failed: [12] Cannot allocate memory [1] 16589 segmentation fault (core dumped) php poc.php ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=73122&edit=1

« previous php.bugs (#235914) next »