Bug #66112 [Com]: Use after free condition in SOAP extension (segfault)

From: Date: Mon, 18 Nov 2013 12:53:25 +0000
Subject: Bug #66112 [Com]: Use after free condition in SOAP extension (segfault)
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-182810@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=66112&edit=1 ID: 66112 Comment by: martin dot koegler at brz dot gv dot at Reported by: martin dot koegler at brz dot gv dot at Summary: Use after free condition in SOAP extension (segfault) Status: Open Type: Bug Package: SOAP related Operating System: Any PHP Version: 5.5.6 Block user comment: N Private report: N New Comment: Workaround: --- php-5.5.5/ext/soap/soap.c.orig 2013-11-15 16:08:13.298600954 +0100 +++ php-5.5.5/ext/soap/soap.c 2013-11-15 17:21:04.504212497 +0100 @@ -2702,6 +2702,7 @@ SOAP_GLOBAL(features) = 0; } + zend_try { if (sdl != NULL) { fn = get_function(sdl, function); if (fn != NULL) { @@ -2811,6 +2812,9 @@ MAKE_COPY_ZVAL(&return_value, exception); zend_throw_exception_object(exception TSRMLS_CC); } + } zend_catch { + _bailout = 1; + } zend_end_try(); if (SOAP_GLOBAL(encoding) != NULL) { xmlCharEncCloseFunc(SOAP_GLOBAL(encoding)); @@ -2820,6 +2824,8 @@ SOAP_GLOBAL(class_map) = old_class_map; SOAP_GLOBAL(encoding) = old_encoding; SOAP_GLOBAL(sdl) = old_sdl; + if (_bailout) + zend_bailout(); SOAP_CLIENT_END_CODE(); } Previous Comments: ------------------------------------------------------------------------ [2013-11-18 12:52:46] martin dot koegler at brz dot gv dot at Description: ------------ do_soap_call (ext/soap/soap.c) saves the values of SOAP_GLOBAL(typemap) (and other variables) and overrides them. After doing its work, it restores the old values. If the code in between invokes zend_bailout (eg. because of an error/exception), the zend_bailout is catched after the restore of the values. So SOAP_GLOBAL(typemap) is not restored. The remaining code executes using a invalid, potential freed typemap. Actual result: -------------- Segfault ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=66112&edit=1

« previous php.bugs (#182810) next »