Re: cvs: php4(PHP_4_0_7) /main rfc1867.c

From: Date: Thu, 28 Feb 2002 09:42:09 +0000
Subject: Re: cvs: php4(PHP_4_0_7) /main rfc1867.c
References: 1  Groups: php.cvs 
Request: Send a blank email to php-cvs+get-9501@lists.php.net to get a copy of this message
Yeah, that is pretty much what I could gather as well. It was the segfault on accessing NULL+1 that can be generated with a funky file upload header that I am not 100% confident can not somehow be exploited in some weird manner. Guess there is no real way to get that to branch to arbitrary code somewhere though. -Rasmus On Thu, 28 Feb 2002, Stefan Esser wrote: > Hello, > > Ehmm lets assume the memchr returns the last byte of the buffer. > The buffer is zero so the +1 will set loc to point to a '\0' > that means the while loop will not be called because '\0' is not > ' ' or '\t'. rem will become -1 and ptr will point to '\0'. > The strcasecmp will fail because of that. And because rem is below 31 > it will leave the function. > > Now assume the memchr returns NULL. This will crash at the beginning > of the while loop. > > Now assume we execute the inner while loop atleast once. > Because rem is not decreased within this loop it cannot become negative > and the worst thing that could happen is that memchr returns the last > char... > You can continue at the top of this mail to see what will happen... > > So all that is possible in 4.1.2 is to cause a segfault. > But the same was possible before, too. > > Stefan Esser >

« previous php.cvs (#9501) next »