Re: Re: php4 /ext/standard file.c formatted_print.c

From: Date: Sat, 11 Jan 2003 23:52:47 +0000
Subject: Re: Re: php4 /ext/standard file.c formatted_print.c
References: 1 2 3 4 5 6 7  Groups: php.dev 
Request: Send a blank email to php-dev+get-93357@lists.php.net to get a copy of this message
On Sun, Jan 12, 2003 at 12:12:39AM +0100, Sascha Schumann wrote: > As many past security advisories have shown, signedness > issues are the frequent cause for severe vulnerabilities in > software (recent examples include MySQL, OpenBSD kernel). Actually codes like below produce vulnerble runtimes because the length of string is expected to be a positive integer value... int maxlen; ... if ((int)Z_STRLEN_P(length) > maxlen) { RETURN_FALSE; } memcpy(allocated_buf, Z_STRVAL_P(length), Z_STRLEN_P(length)); > Any objections? No objection from me. Moriyoshi

« previous php.dev (#93357) next »