Re: Re: com php-src: fix several datatype mismatches: Zend/zend_API.h ext/standard/basic_functions.c ext/standard/basic_functions.h
| From: | Daniel Zulla | Date: | Wed, 22 Oct 2014 20:09:22 +0000 |
| Subject: | Re: Re: com php-src: fix several datatype mismatches: Zend/zend_API.h ext/standard/basic_functions.c ext/standard/basic_functions.h | ||
| References: | 1 2 3 4 5 6 | Groups: | php.cvs php.internals |
| Request: | Send a blank email to internals+get-78245@lists.php.net to get a copy of this message | ||
QUERY_STRING is limited; but what about POST/etc.?
I think giving attackers a way to turn a variable into an array is a problem at large.
On 22 Oct 2014, at 22:08, Anatol Belski <ab@php.net> wrote:
> On Wed, October 22, 2014 21:18, Daniel Zulla wrote:
>> What happens if you exceed uint32?
>>
>>
>> Just curious, security-wise, because AFAIR exceeding uint32 would be
>> possible through superglobals only, which a potential attacker could abuse.
>>
>>
>> param=foo
>>
>> param[a]=foo¶m[b]=foo¶m[c]=foo¶m[…]=foo (reaching uin32+1)
>>
> Daniel,
>
> QUERY_STRING length has a limitation. And, unsigned will roll over once
> exceeded. So without looking deeply at the code, it might just reset the
> whole HashTable to the zero size, but the internal counters will be blown.
>
> Regards
>
> Anatol
>
>
>