Doc #61531 [Ana->Csd]: Integer Overflow in all printf functions

From: Date: Mon, 12 Nov 2012 02:15:06 +0000
Subject: Doc #61531 [Ana->Csd]: Integer Overflow in all printf functions
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-9082@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=61531&edit=1 ID: 61531 Updated by: aharvey@php.net Reported by: iblue at gmx dot net Summary: Integer Overflow in all printf functions -Status: Analyzed +Status: Closed Type: Documentation Problem -Package: Strings related +Package: Documentation problem Operating System: GNU/Linux PHP Version: 5.4.0 -Assigned To: +Assigned To: aharvey Block user comment: N Private report: N New Comment: This bug has been fixed in the documentation's XML sources. Since the online and downloadable versions of the documentation need some time to get updated, we would like to ask you to be a bit patient. Thank you for the report, and for helping us make our documentation better. Previous Comments: ------------------------------------------------------------------------ [2012-11-12 02:14:37] aharvey@php.net Automatic comment from SVN on behalf of aharvey Revision: http://svn.php.net/viewvc/?view=revision&amp;revision=328312 Log: Add a note about position specifiers respecting PHP_INT_MAX. Fixes doc bug #61531 (Integer Overflow in all printf functions). ------------------------------------------------------------------------ [2012-03-31 07:10:43] yohgaki@php.net Changed to Doc problem. ------------------------------------------------------------------------ [2012-03-28 08:25:37] yohgaki@php.net php_sprintf_getnumber() compares with INT_MAX and returns -1, so this happens in 64 bit architecture, too. ------------------------------------------------------------------------ [2012-03-28 08:21:51] yohgaki@php.net This happens because argnum is int and php_sprintf_getnumber() just returns -1 when there is overflow. ext/standard/formatted_print.c --------- if (format[temppos] == '$') { argnum = php_sprintf_getnumber(format, &inpos); if (argnum <= 0) { efree(result); efree(args); php_error_docref(NULL TSRMLS_CC, E_WARNING, "Argument number must be greater than zero"); return NULL; } multiuse = 1; inpos++; /* skip the '$' */ } else { ------------- I don't think we have to deal this more gracefully. Anyone? ------------------------------------------------------------------------ [2012-03-27 21:07:12] iblue at gmx dot net Description: ------------ There is an integer overflow in *printf. Test script: --------------- <?php echo sprintf('%2147483646$s', "foo"); echo sprintf('%2147483647$s', "foo"); Expected result: ---------------- PHP Warning: sprintf(): Too few arguments in /home/iblue/test.php on line 2 PHP Warning: sprintf(): Too few arguments in /home/iblue/test.php on line 3 Actual result: -------------- PHP Warning: sprintf(): Too few arguments in /home/iblue/test.php on line 2 PHP Warning: sprintf(): Argument number must be greater than zero in /home/iblue/test.php on line 3 ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=61531&edit=1

« previous php.doc.bugs (#9082) next »