Re: Re: com php-src: fix several datatype mismatches: Zend/zend_API.h ext/standard/basic_functions.c ext/standard/basic_functions.h

From: Date: Wed, 22 Oct 2014 20:09:22 +0000
Subject: Re: Re: com php-src: fix several datatype mismatches: Zend/zend_API.h ext/standard/basic_functions.c ext/standard/basic_functions.h
References: 1 2 3 4 5 6  Groups: php.cvs php.internals 
Request: Send a blank email to internals+get-78245@lists.php.net to get a copy of this message
QUERY_STRING is limited; but what about POST/etc.? I think giving attackers a way to turn a variable into an array is a problem at large. On 22 Oct 2014, at 22:08, Anatol Belski <ab@php.net> wrote: > On Wed, October 22, 2014 21:18, Daniel Zulla wrote: >> What happens if you exceed uint32? >> >> >> Just curious, security-wise, because AFAIR exceeding uint32 would be >> possible through superglobals only, which a potential attacker could abuse. >> >> >> param=foo >> >> param[a]=foo&param[b]=foo&param[c]=foo&param[…]=foo (reaching uin32+1) >> > Daniel, > > QUERY_STRING length has a limitation. And, unsigned will roll over once > exceeded. So without looking deeply at the code, it might just reset the > whole HashTable to the zero size, but the internal counters will be blown. > > Regards > > Anatol > > >

« previous php.internals (#78245) next »