News Feed
Jobs Feed
Sections




News Archive
Looking for more information on how to do PHP the right way? Check out PHP: The Right Way

PHP Security Blog:
Chunk_split() Overflow not fixed at all...
June 05, 2007 @ 07:41:00

In this new post to the PHP Security blog, Stefan Esser points out that an issue that was previously marked as corrected - a problem with the chunk_split function - hasn't completely been corrected.

This [bugfix] fixes the chunk_split() overflow (found by SEC-CONSULT) that was according to the PHP 5.2.3 release notes already fixed. The original fix was however not only broken but complete nonsense. If you can read C you will see that the integer overflow was not fixed in PHP 5.2.3 but simply moved into a separate line and an additional bogus if clause was added.

Stefan includes a simple four line code example to illustrate his point.

0 comments voice your opinion now!
chunksplit overflow bug chunksplit overflow bug


blog comments powered by Disqus

Similar Posts

Zend Developer Zone: Announcing the May 2011 Zend Framework Bug-Hunt

DZone.com: File Path Injection in PHP <= 5.3.6 File Update (CVE 2011-2202)

Padraic Brady's Blog: A Guide To Zend Framework Bug Hunt Days

Pierre-Alain Joye's Blog: Zip 1.4.0, let comment it!

Zend Developer Zone: Why Should I Care What Server My Application is Running On?


Community Events











Don't see your event here?
Let us know!


composer release code hhvm package introduction install hack language unittest example facebook opinion symfony2 framework overview podcast application security component

All content copyright, 2014 PHPDeveloper.org :: info@phpdeveloper.org - Powered by the Solar PHP Framework