php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #73177 String size overflow in "addcslashes"
Submitted: 2016-09-26 12:29 UTC Modified: 2016-09-27 10:41 UTC
From: david dot kurz at majorsecurity dot com Assigned:
Status: Not a bug Package: *General Issues
PHP Version: 5.6.26 OS: -Ubuntu SMP Fri Feb 19 14:27:58
Private report: No CVE-ID: None
Welcome back! If you're the original bug submitter, here's where you can edit the bug or add additional notes.
If you forgot your password, you can retrieve your password here.
Password:
Status:
Package:
Bug Type:
Summary:
From: david dot kurz at majorsecurity dot com
New email:
PHP Version: OS:

 

 [2016-09-26 12:29 UTC] david dot kurz at majorsecurity dot com
Description:
------------
There seems to be a String size overflow in "addcslashes()".

Test script:
---------------
============================
ENVIRONMENT:
============================
./sapi/cli/php -v
PHP 5.6.26 (cli) (built: Sep 26 2016 13:46:50) 
Copyright (c) 1997-2016 The PHP Group
Zend Engine v2.6.0, Copyright (c) 1998-2016 Zend Technologies

============================
Proof of Concept PHP Code:
============================
<?php

ini_set('memory_limit', -1);
$str = str_repeat("'", 0xffffffff/4+1);
$overflow = addcslashes($str, "'");
var_dump(strlen($overflow));

?>
============================

============================
Output:
============================
Fatal error: String size overflow in /data/home/secalert/Desktop/afl-2.34b/php-5.6.26/_overflows/addcslashes_01.php

============================
GDB:
============================
sec@alert:~/Desktop/afl-2.34b/php-5.6.26$ gdb -q -iex  "set auto-load safe-path /" ./sapi/cli/php
Reading symbols from ./sapi/cli/php...done.
(gdb) run /data/home/secalert/Desktop/afl-2.34b/php-5.6.26/_overflows/addcslashes_01.php

Starting program: /data/home/secalert/Desktop/afl-2.34b/php-5.6.26/_overflows/addcslashes_01.php

[Thread debugging using libthread_db enabled]
Using host libthread_db library "/lib/x86_64-linux-gnu/libthread_db.so.1".

Fatal error: String size overflow in /data/home/secalert/Desktop/afl-2.34b/php-5.6.26/_overflows/addcslashes_01.php on line 5
[Inferior 1 (process 21576) exited with code 0377]
(gdb) bt



Expected result:
----------------
There should be an exception handler and none overflow.

Actual result:
--------------
There seems to be a String size overflow in "addcslashes()".

Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2016-09-26 21:43 UTC] david dot kurz at majorsecurity dot com
Hi again. 
I originally found this in PHP 5.5.9 and there it had the overflow. 
But after re-investigation the finding for PHP 5.5.26 today it seems to be a false-positive.

It now raises "zend_throw_error(NULL, "String size overflow");" which i believe is fine. 

Sorry for any confusion.
 [2016-09-27 10:41 UTC] yohgaki@php.net
-Status: Open +Status: Not a bug
 [2016-09-27 10:41 UTC] yohgaki@php.net
Reporter confirmed.
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Wed Oct 07 11:00:02 2026 UTC