Re: com php-src: Fixed bug #71906: AddressSanitizer: negative-size-param (-1) in mbfl_strcut: ext/mbstring/libmbfl/mbfl/mbfilter.c
| From: | Yasuo Ohgaki | Date: | Tue, 29 Mar 2016 07:24:58 +0000 |
| Subject: | Re: com php-src: Fixed bug #71906: AddressSanitizer: negative-size-param (-1) in mbfl_strcut: ext/mbstring/libmbfl/mbfl/mbfilter.c | ||
| References: | 1 2 3 | Groups: | php.cvs |
| Request: | Send a blank email to php-cvs+get-91516@lists.php.net to get a copy of this message | ||
Hi Stas,
On Tue, Mar 29, 2016 at 4:16 PM, Stanislav Malyshev <smalyshev@gmail.com> wrote:
>> It seems effective changes are these excluding WS changes.
>>
>> These changes are
>>
>> X + A >= B
>> to
>> A >= B - X
>>
>> Does this really fix issue?
>
> I think it does. Unless you can show me wrong :)
>
>> My first impression of this bug's cause of signed vs. unsigned int difference.
>> i.e. Mbstring uses unsigned int for string length. IIRC.
>
> Not sure what you mean. The issue was that X+A was overflowing since A
> was very big, and thus even though A was too big X+A >= B condition did
> not check.
If overflow is the problem
- if ((start - string->val) + length >=
(int)string->len) {
+ if (length >= (int)string->len - (start -
string->val)) {
end = string->val + string->len;
This
end = string->val + string->len;
could be problem, perhaps.
It seems the fix is incomplete or missing some thing.
I'm looking diff only, so I could be wrong though.
Regards,
--
Yasuo Ohgaki
yohgaki@ohgaki.net