|
php.net | support | documentation | report a bug | advanced search | search howto | statistics | random bug | login |
PatchesPull RequestsHistoryAllCommentsChangesGit/SVN commits
[2016-09-26 21:43 UTC] david dot kurz at majorsecurity dot com
[2016-09-27 10:41 UTC] yohgaki@php.net
-Status: Open
+Status: Not a bug
[2016-09-27 10:41 UTC] yohgaki@php.net
|
|||||||||||||||||||||||||||
Copyright © 2001-2026 The PHP GroupAll rights reserved. |
Last updated: Wed Oct 07 10:00:01 2026 UTC |
Description: ------------ There seems to be a String size overflow in "addcslashes()". Test script: --------------- ============================ ENVIRONMENT: ============================ ./sapi/cli/php -v PHP 5.6.26 (cli) (built: Sep 26 2016 13:46:50) Copyright (c) 1997-2016 The PHP Group Zend Engine v2.6.0, Copyright (c) 1998-2016 Zend Technologies ============================ Proof of Concept PHP Code: ============================ <?php ini_set('memory_limit', -1); $str = str_repeat("'", 0xffffffff/4+1); $overflow = addcslashes($str, "'"); var_dump(strlen($overflow)); ?> ============================ ============================ Output: ============================ Fatal error: String size overflow in /data/home/secalert/Desktop/afl-2.34b/php-5.6.26/_overflows/addcslashes_01.php ============================ GDB: ============================ sec@alert:~/Desktop/afl-2.34b/php-5.6.26$ gdb -q -iex "set auto-load safe-path /" ./sapi/cli/php Reading symbols from ./sapi/cli/php...done. (gdb) run /data/home/secalert/Desktop/afl-2.34b/php-5.6.26/_overflows/addcslashes_01.php Starting program: /data/home/secalert/Desktop/afl-2.34b/php-5.6.26/_overflows/addcslashes_01.php [Thread debugging using libthread_db enabled] Using host libthread_db library "/lib/x86_64-linux-gnu/libthread_db.so.1". Fatal error: String size overflow in /data/home/secalert/Desktop/afl-2.34b/php-5.6.26/_overflows/addcslashes_01.php on line 5 [Inferior 1 (process 21576) exited with code 0377] (gdb) bt Expected result: ---------------- There should be an exception handler and none overflow. Actual result: -------------- There seems to be a String size overflow in "addcslashes()".