Likes Likes:  0
Resultaten 1 tot 3 van de 3
Geen
  1. #1
    Stefan Esser
    RE: FUD-ALARM: @(#)Mordred Labs advisory - Integer overflow in PHP memory allocator
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    RE: FUD-ALARM: @(#)Mordred Labs advisory - Integer overflow in PHP memory allocator


    Hello Mr. Mordred (and the rest of the Bugtraq readers),

    I happily repeat everything I wrote to you before. Your advisories are
    FUD. You release an advisory called: Integer overflow in PHP memory
    allocator, rate it as High Risk, but you present the reader some stupid
    crash bug in the socket extension that is marked as experimental and
    is not enabled by default. I told you before, that the integer over-
    flow cannot be used to exploit PHP. If you find a single emalloc call
    where some user supplied value is able to allocate a block in the size
    of 4 Gigabyte (on 32bit maschines), then you have found a vulnerability.
    Just stating that there is a possible integer overflow if someone
    allocates more than 2^32-7 bytes (2^64-7 bytes) is a joke. A vulnerability
    that cannot be exploited may not be rated as: high risk. This can be
    compared to calling strcpy a security vulnerability because it can be
    used by a stupid PHP core/extension programmer to produce a bufferoverflow.

    Stefan Esser


    --

    --------------------------------------------------------------------------
    Stefan Esser s.esser@e-matters.de
    e-matters Security http://security.e-matters.de/

    GPG-Key gpg --keyserver pgp.mit.edu --recv-key 0xCF6CAE69
    Key fingerprint B418 B290 ACC0 C8E5 8292 8B72 D6B0 7704 CF6C AE69
    --------------------------------------------------------------------------
    Did I help you? Consider a gift: http://wishlist.suspekt.org/
    --------------------------------------------------------------------------


  2. #2
    Dullien@gmx.de
    RE: FUD-ALARM: @(#)Mordred Labs advisory - Integer overflow in PHP memory allocator
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: @(#)Mordred Labs advisory - Integer overflow in PHP memory allocator

    Hey Mr. Mordred, all,

    > In PHP emalloc() function implements the error safe wrapper around
    > malloc().
    > Unfortunately this function suffers from an integer overflow and
    > considering the fact that emalloc() is used in many places around PHP
    > source code, it may lead to many serious security issues.


    IIRC this bug was mentioned in a talk at last summers Black Hat conference.

    http://www.blackhat.com/html/bh-usa-...kers.html#Dowd

    Cheers,
    dullien@gmx.de

    --
    +++ GMX - Mail, Messaging & more http://www.gmx.net +++
    Bitte lächeln! Fotogalerie online mit GMX ohne eigene Homepage!


  3. #3
    RE: FUD-ALARM: @(#)Mordred Labs advisory - Integer overflow in PHP memory allocator
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    RE: FUD-ALARM: @(#)Mordred Labs advisory - Integer overflow in PHP memory allocator


    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    Hi

    Stefan nicely asked me to provide real examples in the PHP source code
    in which was used something like - emalloc(userinput).
    In the advisory has been 2 examples, first used emalloc(userinput +1),

    second - emalloc(userinput + 2). Guess that was enough for understanding
    and fixing the issue. Really sorry if someone did not get the point,
    we don't provide tech support on the subject of our advisories...someday
    maybe...As for the note that this is a experimental extension and not
    enabled by default - looks like there are some problems with installing
    sockets extension, just add --with-sockets option to configure script.

    Another example of insecure emalloc() call - mhash_keygen_s2k() function
    in the mhash extension which uses emalloc(userinput + 1).

    Best regards.
    // Sir Mordred


    -----BEGIN PGP SIGNATURE-----
    Version: Hush 2.2 (Java)
    Note: This signature can be verified at https://www.hushtools.com/verify

    wmAEARECACAFAj6Do8gZHHNpci5tb3JkcmVkQGh1c2htYWlsLm NvbQAKCRAOkXvN4BZr
    fDiiAKC2Dcu2cnqYrHD76wT8Qw9trtlBXwCgpuij68JVA18Lcv 3g5vXpPDVDmQM=
    =qSXr
    -----END PGP SIGNATURE-----




    Concerned about your privacy? Follow this link to get
    FREE encrypted email: https://www.hushmail.com/?l=2

    Big $$$ to be made with the HushMail Affiliate Program:
    https://www.hushmail.com/about.php?s...ffiliate&l=427

Webhostingtalk.nl

Contact

  • Rokin 113-115
  • 1012 KP, Amsterdam
  • Nederland
  • Contact
© Copyright 2001-2026 Webhostingtalk.nl.
Web Statistics