Re: cvs: php4(PHP_4_0_7) /main rfc1867.c
| From: | Rasmus Lerdorf | Date: | Thu, 28 Feb 2002 09:42:09 +0000 |
| Subject: | Re: cvs: php4(PHP_4_0_7) /main rfc1867.c | ||
| References: | 1 | Groups: | php.cvs |
| Request: | Send a blank email to php-cvs+get-9501@lists.php.net to get a copy of this message | ||
Yeah, that is pretty much what I could gather as well. It was the
segfault on accessing NULL+1 that can be generated with a funky file
upload header that I am not 100% confident can not somehow be exploited in
some weird manner. Guess there is no real way to get that to branch to
arbitrary code somewhere though.
-Rasmus
On Thu, 28 Feb 2002, Stefan Esser wrote:
> Hello,
>
> Ehmm lets assume the memchr returns the last byte of the buffer.
> The buffer is zero so the +1 will set loc to point to a '\0'
> that means the while loop will not be called because '\0' is not
> ' ' or '\t'. rem will become -1 and ptr will point to '\0'.
> The strcasecmp will fail because of that. And because rem is below 31
> it will leave the function.
>
> Now assume the memchr returns NULL. This will crash at the beginning
> of the while loop.
>
> Now assume we execute the inner while loop atleast once.
> Because rem is not decreased within this loop it cannot become negative
> and the worst thing that could happen is that memchr returns the last
> char...
> You can continue at the top of this mail to see what will happen...
>
> So all that is possible in 4.1.2 is to cause a segfault.
> But the same was possible before, too.
>
> Stefan Esser
>