Bug #81370 [Asn->Nab]: Possible divide by zero bug in string.c

From: Date: Thu, 19 Aug 2021 12:34:34 +0000
Subject: Bug #81370 [Asn->Nab]: Possible divide by zero bug in string.c
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-235952@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81370&edit=1 ID: 81370 Updated by: cmb@php.net Reported by: yguoaz at gmail dot com Summary: Possible divide by zero bug in string.c -Status: Assigned +Status: Not a bug Type: Bug Package: Strings related Operating System: Linux PHP Version: master-Git-2021-08-18 (Git) Assigned To: cmb Block user comment: N Private report: N New Comment: Fine. Closing then. Previous Comments: ------------------------------------------------------------------------ [2021-08-19 12:21:56] yguoaz at gmail dot com This should be correct. Thanks for your clarification. ------------------------------------------------------------------------ [2021-08-19 11:44:33] cmb@php.net > chk starts as strlen(text) and is decreased by at most 1 on each > loop iteration. There are strlen(text) loop iterations. So chk > will not reach 0 within the loop. That is correct. Or can you prove that this is wrong? A single example would be sufficient. ------------------------------------------------------------------------ [2021-08-18 09:48:55] nikic@php.net chk starts as strlen(text) and is decreased by at most 1 on each loop iteration. There are strlen(text) loop iterations. So chk will not reach 0 within the loop. ------------------------------------------------------------------------ [2021-08-18 08:36:42] yguoaz at gmail dot com chk is also decreased inside the loop. So I think it has a chance to equal the zero value. Do you mean ZSTR_LEN(text)and linelength must be equal? ------------------------------------------------------------------------ [2021-08-18 08:19:03] nikic@php.net This also requires chk==0, which as far as I can see can't occur for the linelength==0 case. text being an empty string is handled early. Then chk is set to the length of text and the loop also goes over the length of text. The allocation management in this function looks pretty wild though, it might make sense to rewrite it to use smart_str. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=81370 -- Edit this bug report at https://bugs.php.net/bug.php?id=81370&edit=1

« previous php.bugs (#235952) next »