Re: Re: php4 /ext/standard file.c formatted_print.c
| From: | Moriyoshi Koizumi | Date: | Sat, 11 Jan 2003 23:52:47 +0000 |
| Subject: | Re: Re: php4 /ext/standard file.c formatted_print.c | ||
| References: | 1 2 3 4 5 6 7 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-93357@lists.php.net to get a copy of this message | ||
On Sun, Jan 12, 2003 at 12:12:39AM +0100, Sascha Schumann wrote:
> As many past security advisories have shown, signedness
> issues are the frequent cause for severe vulnerabilities in
> software (recent examples include MySQL, OpenBSD kernel).
Actually codes like below produce vulnerble runtimes because
the length of string is expected to be a positive integer value...
int maxlen;
...
if ((int)Z_STRLEN_P(length) > maxlen) {
RETURN_FALSE;
}
memcpy(allocated_buf, Z_STRVAL_P(length), Z_STRLEN_P(length));
> Any objections?
No objection from me.
Moriyoshi