Re: com php-src: Fixed bug #71906: AddressSanitizer: negative-size-param (-1) in mbfl_strcut: ext/mbstring/libmbfl/mbfl/mbfilter.c
| From: | Yasuo Ohgaki | Date: | Tue, 29 Mar 2016 07:13:45 +0000 |
| Subject: | Re: com php-src: Fixed bug #71906: AddressSanitizer: negative-size-param (-1) in mbfl_strcut: ext/mbstring/libmbfl/mbfl/mbfilter.c | ||
| References: | 1 | Groups: | php.cvs |
| Request: | Send a blank email to php-cvs+get-91513@lists.php.net to get a copy of this message | ||
Hi Stas,
On Mon, Mar 28, 2016 at 5:22 PM, Stanislav Malyshev <stas@php.net> wrote:
> @@ -1501,7 +1501,7 @@ mbfl_strcut(
> if (encoding->flag & (MBFL_ENCTYPE_WCS2BE | MBFL_ENCTYPE_WCS2LE)) {
> from &= -2;
>
> - if (from + length >= string->len) {
> + if (length >= string->len - from) {
> length = string->len - from;
> }
>
> @@ -1510,14 +1510,14 @@ mbfl_strcut(
> } else if (encoding->flag & (MBFL_ENCTYPE_WCS4BE | MBFL_ENCTYPE_WCS4LE))
> {
> from &= -4;
>
> - if (from + length >= string->len) {
> + if (length >= string->len - from) {
> length = string->len - from;
> }
>
> start = string->val + from;
> end = start + (length & -4);
> } else if ((encoding->flag & MBFL_ENCTYPE_SBCS)) {
> - if (from + length >= string->len) {
> + if (length >= string->len - from) {
> length = string->len - from;
> }
>
> @@ -1539,7 +1539,7 @@ mbfl_strcut(
> start = p;
>
> /* search end position */
> - if ((start - string->val) + length >= (int)string->len) {
> + if (length >= (int)string->len - (start - string->val)) {
> end = string->val + string->len;
> } else {
> for (q = p + length; p < q; p += (m = mbtab[*p]));
It seems effective changes are these excluding WS changes.
These changes are
X + A >= B
to
A >= B - X
Does this really fix issue?
My first impression of this bug's cause of signed vs. unsigned int difference.
i.e. Mbstring uses unsigned int for string length. IIRC.
Regards,
--
Yasuo Ohgaki
yohgaki@ohgaki.net