Doc #61531 [Ana->Csd]: Integer Overflow in all printf functions
| From: | aharvey@php.net | Date: | Mon, 12 Nov 2012 02:15:06 +0000 |
| Subject: | Doc #61531 [Ana->Csd]: Integer Overflow in all printf functions | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-9082@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=61531&edit=1
ID: 61531
Updated by: aharvey@php.net
Reported by: iblue at gmx dot net
Summary: Integer Overflow in all printf functions
-Status: Analyzed
+Status: Closed
Type: Documentation Problem
-Package: Strings related
+Package: Documentation problem
Operating System: GNU/Linux
PHP Version: 5.4.0
-Assigned To:
+Assigned To: aharvey
Block user comment: N
Private report: N
New Comment:
This bug has been fixed in the documentation's XML sources. Since the
online and downloadable versions of the documentation need some time
to get updated, we would like to ask you to be a bit patient.
Thank you for the report, and for helping us make our documentation better.
Previous Comments:
------------------------------------------------------------------------
[2012-11-12 02:14:37] aharvey@php.net
Automatic comment from SVN on behalf of aharvey
Revision: http://svn.php.net/viewvc/?view=revision&revision=328312
Log: Add a note about position specifiers respecting PHP_INT_MAX.
Fixes doc bug #61531 (Integer Overflow in all printf functions).
------------------------------------------------------------------------
[2012-03-31 07:10:43] yohgaki@php.net
Changed to Doc problem.
------------------------------------------------------------------------
[2012-03-28 08:25:37] yohgaki@php.net
php_sprintf_getnumber() compares with INT_MAX and returns -1, so this happens in
64 bit architecture, too.
------------------------------------------------------------------------
[2012-03-28 08:21:51] yohgaki@php.net
This happens because argnum is int and php_sprintf_getnumber() just returns -1
when there is overflow.
ext/standard/formatted_print.c
---------
if (format[temppos] == '$') {
argnum = php_sprintf_getnumber(format, &inpos);
if (argnum <= 0) {
efree(result);
efree(args);
php_error_docref(NULL TSRMLS_CC, E_WARNING, "Argument number
must be greater than zero");
return NULL;
}
multiuse = 1;
inpos++; /* skip the '$' */
} else {
-------------
I don't think we have to deal this more gracefully. Anyone?
------------------------------------------------------------------------
[2012-03-27 21:07:12] iblue at gmx dot net
Description:
------------
There is an integer overflow in *printf.
Test script:
---------------
<?php
echo sprintf('%2147483646$s', "foo");
echo sprintf('%2147483647$s', "foo");
Expected result:
----------------
PHP Warning: sprintf(): Too few arguments in /home/iblue/test.php on line 2
PHP Warning: sprintf(): Too few arguments in /home/iblue/test.php on line 3
Actual result:
--------------
PHP Warning: sprintf(): Too few arguments in /home/iblue/test.php on line 2
PHP Warning: sprintf(): Argument number must be greater than zero in
/home/iblue/test.php on line 3
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=61531&edit=1