Sec Bug->Bug #81370 [Opn]: Possible divide by zero bug in string.c

From: Date: Wed, 18 Aug 2021 04:04:53 +0000
Subject: Sec Bug->Bug #81370 [Opn]: Possible divide by zero bug in string.c
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-235918@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81370&edit=1 ID: 81370 Updated by: stas@php.net Reported by: yguoaz at gmail dot com Summary: Possible divide by zero bug in string.c Status: Open -Type: Security +Type: Bug Package: *General Issues Operating System: Linux PHP Version: master-Git-2021-08-18 (Git) Block user comment: N Private report: Y Previous Comments: ------------------------------------------------------------------------ [2021-08-18 03:40:40] yguoaz at gmail dot com Description: ------------ In the file ext/standard/string.c, the PHP_FUNCTION wordwrap has the following code: PHP_FUNCTION(wordwrap) { zend_long linelength = 75; ZEND_PARSE_PARAMETERS_START(1, 4) ... Z_PARAM_LONG(linelength) Z_PARAM_STRING(breakchar, breakchar_len) Z_PARAM_BOOL(docut) ZEND_PARSE_PARAMETERS_END(); ... if (linelength == 0 && docut) { RETURN_THROWS(); } if (breakchar_len == 1 && !docut) { ... } else { ... for (current = 0; current < (zend_long)ZSTR_LEN(text); current++) { if (chk == 0) { alloced += (size_t) (((ZSTR_LEN(text) - current + 1)/linelength + 1) * breakchar_len) + 1; newtext = zend_string_extend(newtext, alloced, 0); chk = (size_t) ((ZSTR_LEN(text) - current)/linelength) + 1; } ... } } } When the parameters satisfy linelength == 0 && docut == 0 && breakchar_len > 1, the variable linelength may be used as a divisor in the for loop, leading to a divide by zero bug. Here is the link to the related code location: https://github.com/php/php-src/blob/e86a0a905dd091a82bea2ff56845297171ea7249/ext/standard/string.c#L954 ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=81370&edit=1

« previous php.bugs (#235918) next »