oss-sec mailing list archives

CVE Request: ZIP Integer Overflow leads to writing past heap boundary


From: Emmanuel Law <emmanuel.law () gmail com>
Date: Wed, 18 Mar 2015 20:19:26 +1300

Hi,

found an integer overflow in PHP. When processing a malform zip file with
many entires, it leads to a heap overflow.

Affected Version <= PHP 5.6.6
Bug Report: https://bugs.php.net/bug.php?id=69253
Patch:
https://github.com/php/php-src/commit/ef8fc4b53d92fbfcd8ef1abbd6f2f5fe2c4a11e5

Could you please assign a CVE-ID for it?

Thanks,

Emmanuel

Current thread: