Bug #66112 [Com]: Use after free condition in SOAP extension (segfault)
| From: | martin dot koegler at brz dot gv dot at | Date: | Mon, 18 Nov 2013 12:55:05 +0000 |
| Subject: | Bug #66112 [Com]: Use after free condition in SOAP extension (segfault) | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-182811@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=66112&edit=1
ID: 66112
Comment by: martin dot koegler at brz dot gv dot at
Reported by: martin dot koegler at brz dot gv dot at
Summary: Use after free condition in SOAP extension
(segfault)
Status: Open
Type: Bug
Package: SOAP related
Operating System: Any
PHP Version: 5.5.6
Block user comment: N
Private report: N
New Comment:
test1.php:
<?php
function Mist($p)
{
$client=new soapclient("test.wsdl",
array('typemap'=>array(array("type_ns"=>"uri:mist",
"type_name"=>"A"))));
try{
$client->Mist(array("XX"=>"xx"));
}catch(SoapFault $x){}
return array("A"=>"ABC","B"=>"sss");
}
$s = new SoapServer("test.wsdl",
array('typemap'=>array(array("type_ns"=>"uri:mist",
"type_name"=>"A"))));
$s->addFunction("Mist");
$_SERVER["REQUEST_METHOD"] = "POST";
$HTTP_RAW_POST_DATA=<<<EOF
<?xml version="1.0" encoding="UTF-8"?>
<soapenv:Envelope xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/"
xmlns:uri="uri:mist">
<soapenv:Header/>
<soapenv:Body>
<uri:Request><uri:A>XXX</uri:A><uri:B>yyy</uri:B></uri:Request>
</soapenv:Body>
</soapenv:Envelope>
EOF;
$s->handle($HTTP_RAW_POST_DATA);
?>
Previous Comments:
------------------------------------------------------------------------
[2013-11-18 12:53:25] martin dot koegler at brz dot gv dot at
Workaround:
--- php-5.5.5/ext/soap/soap.c.orig 2013-11-15 16:08:13.298600954 +0100
+++ php-5.5.5/ext/soap/soap.c 2013-11-15 17:21:04.504212497 +0100
@@ -2702,6 +2702,7 @@
SOAP_GLOBAL(features) = 0;
}
+ zend_try {
if (sdl != NULL) {
fn = get_function(sdl, function);
if (fn != NULL) {
@@ -2811,6 +2812,9 @@
MAKE_COPY_ZVAL(&return_value, exception);
zend_throw_exception_object(exception TSRMLS_CC);
}
+ } zend_catch {
+ _bailout = 1;
+ } zend_end_try();
if (SOAP_GLOBAL(encoding) != NULL) {
xmlCharEncCloseFunc(SOAP_GLOBAL(encoding));
@@ -2820,6 +2824,8 @@
SOAP_GLOBAL(class_map) = old_class_map;
SOAP_GLOBAL(encoding) = old_encoding;
SOAP_GLOBAL(sdl) = old_sdl;
+ if (_bailout)
+ zend_bailout();
SOAP_CLIENT_END_CODE();
}
------------------------------------------------------------------------
[2013-11-18 12:52:46] martin dot koegler at brz dot gv dot at
Description:
------------
do_soap_call (ext/soap/soap.c) saves the values of SOAP_GLOBAL(typemap) (and other variables) and
overrides them.
After doing its work, it restores the old values.
If the code in between invokes zend_bailout (eg. because of an error/exception), the zend_bailout is
catched after the restore of the values. So SOAP_GLOBAL(typemap) is not restored.
The remaining code executes using a invalid, potential freed typemap.
Actual result:
--------------
Segfault
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=66112&edit=1