[pull] master from php:master - #1252
Merged
Merged
Conversation
zend_multibyte_detect_utf_encoding() previously advanced the search position by four bytes after each NUL while looking for UTF-32-specific byte orders. When fewer than three bytes remained, the search length underflowed and allowed memchr() to read past the script buffer. Track search positions as offsets and only call memchr() while at least three bytes remain. This also avoids advancing a pointer beyond the script buffer and prevents BOM-less UTF-16 input from being misdetected as UTF-32. Closes #23527
* PHP-8.4: Fix bounds check in multibyte UTF detection (#23527)
* PHP-8.5: Fix bounds check in multibyte UTF detection (#23527)
Use component-first names for validation and percent-encoding helpers, matching the existing component read/write functions.
netsnmp_session_set_contextEngineID() passes an emalloc()'d buffer to snmp_hex_to_binary() with allow_realloc set. A context engine ID longer than the 32-byte buffer makes net-snmp call snmp_realloc() on that pointer, which aborts the process. RFC 3411 caps the engine ID at 32 bytes anyway, so this drops allow_realloc: an oversized value now hits the existing "Bad engine ID value" warning and returns false. Close GH-23456
* PHP-8.4: Fix GH-23453: bad free with a context engine ID longer than 32 bytes
* PHP-8.5: Fix GH-23453: bad free with a context engine ID longer than 32 bytes # Conflicts: # ext/snmp/snmp.c
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
See Commits and Changes for more details.
Created by
pull[bot] (v2.0.0-alpha.4)
Can you help keep this open source service alive? 💖 Please sponsor : )