php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #73177 String size overflow in "addcslashes"
Submitted: 2016-09-26 12:29 UTC Modified: 2016-09-27 10:41 UTC
From: david dot kurz at majorsecurity dot com Assigned:
Status: Not a bug Package: *General Issues
PHP Version: 5.6.26 OS: -Ubuntu SMP Fri Feb 19 14:27:58
Private report: No CVE-ID: None
View Developer Edit
Welcome! If you don't have a Git account, you can't do anything here.
If you reported this bug, you can edit this bug over here.
(description)
Block user comment
Status: Assign to:
Package:
Bug Type:
Summary:
From: david dot kurz at majorsecurity dot com
New email:
PHP Version: OS:

 

 [2016-09-26 12:29 UTC] david dot kurz at majorsecurity dot com
Description:
------------
There seems to be a String size overflow in "addcslashes()".

Test script:
---------------
============================
ENVIRONMENT:
============================
./sapi/cli/php -v
PHP 5.6.26 (cli) (built: Sep 26 2016 13:46:50) 
Copyright (c) 1997-2016 The PHP Group
Zend Engine v2.6.0, Copyright (c) 1998-2016 Zend Technologies

============================
Proof of Concept PHP Code:
============================
<?php

ini_set('memory_limit', -1);
$str = str_repeat("'", 0xffffffff/4+1);
$overflow = addcslashes($str, "'");
var_dump(strlen($overflow));

?>
============================

============================
Output:
============================
Fatal error: String size overflow in /data/home/secalert/Desktop/afl-2.34b/php-5.6.26/_overflows/addcslashes_01.php

============================
GDB:
============================
sec@alert:~/Desktop/afl-2.34b/php-5.6.26$ gdb -q -iex  "set auto-load safe-path /" ./sapi/cli/php
Reading symbols from ./sapi/cli/php...done.
(gdb) run /data/home/secalert/Desktop/afl-2.34b/php-5.6.26/_overflows/addcslashes_01.php

Starting program: /data/home/secalert/Desktop/afl-2.34b/php-5.6.26/_overflows/addcslashes_01.php

[Thread debugging using libthread_db enabled]
Using host libthread_db library "/lib/x86_64-linux-gnu/libthread_db.so.1".

Fatal error: String size overflow in /data/home/secalert/Desktop/afl-2.34b/php-5.6.26/_overflows/addcslashes_01.php on line 5
[Inferior 1 (process 21576) exited with code 0377]
(gdb) bt



Expected result:
----------------
There should be an exception handler and none overflow.

Actual result:
--------------
There seems to be a String size overflow in "addcslashes()".

Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2016-09-26 21:43 UTC] david dot kurz at majorsecurity dot com
Hi again. 
I originally found this in PHP 5.5.9 and there it had the overflow. 
But after re-investigation the finding for PHP 5.5.26 today it seems to be a false-positive.

It now raises "zend_throw_error(NULL, "String size overflow");" which i believe is fine. 

Sorry for any confusion.
 [2016-09-27 10:41 UTC] yohgaki@php.net
-Status: Open +Status: Not a bug
 [2016-09-27 10:41 UTC] yohgaki@php.net
Reporter confirmed.
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Wed Oct 07 10:00:01 2026 UTC