Bug #66112 [Com]: Use after free condition in SOAP extension (segfault)

From: Date: Mon, 18 Nov 2013 12:58:57 +0000
Subject: Bug #66112 [Com]: Use after free condition in SOAP extension (segfault)
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-182812@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=66112&edit=1 ID: 66112 Comment by: martin dot koegler at brz dot gv dot at Reported by: martin dot koegler at brz dot gv dot at Summary: Use after free condition in SOAP extension (segfault) Status: Open Type: Bug Package: SOAP related Operating System: Any PHP Version: 5.5.6 Block user comment: N Private report: N New Comment: Sorry, the wsdl is recognized as spam. test.wsdl - Part 1: <?xml version="1.0" encoding="UTF-8"?> <wsdl:definitions xmlns:tns="uri:mist" xmlns:wsdl="http://schemas.xmlsoap.org/wsdl/" xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:soap="http://schemas.xmlsoap.org/wsdl/soap/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" name="test" targetNamespace="uri:mist"> <wsdl:types> <xs:schema xmlns:xs="http://www.w3.org/2001/XMLSchema" targetNamespace="uri:mist"> <xs:complexType name="T1"> <xs:sequence> <xs:element name="A" type="xsd:string"/><xs:element name="B" type="xsd:string"/> </xs:sequence> </xs:complexType> <xs:element name="Request" type="tns:T1"/><xs:element name="Response" type="tns:T1"/> </xs:schema> </wsdl:types> Previous Comments: ------------------------------------------------------------------------ [2013-11-18 12:55:05] martin dot koegler at brz dot gv dot at test1.php: <?php function Mist($p) { $client=new soapclient("test.wsdl", array('typemap'=>array(array("type_ns"=>"uri:mist", "type_name"=>"A")))); try{ $client->Mist(array("XX"=>"xx")); }catch(SoapFault $x){} return array("A"=>"ABC","B"=>"sss"); } $s = new SoapServer("test.wsdl", array('typemap'=>array(array("type_ns"=>"uri:mist", "type_name"=>"A")))); $s->addFunction("Mist"); $_SERVER["REQUEST_METHOD"] = "POST"; $HTTP_RAW_POST_DATA=<<<EOF <?xml version="1.0" encoding="UTF-8"?> <soapenv:Envelope xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/" xmlns:uri="uri:mist"> <soapenv:Header/> <soapenv:Body> <uri:Request><uri:A>XXX</uri:A><uri:B>yyy</uri:B></uri:Request> </soapenv:Body> </soapenv:Envelope> EOF; $s->handle($HTTP_RAW_POST_DATA); ?> ------------------------------------------------------------------------ [2013-11-18 12:53:25] martin dot koegler at brz dot gv dot at Workaround: --- php-5.5.5/ext/soap/soap.c.orig 2013-11-15 16:08:13.298600954 +0100 +++ php-5.5.5/ext/soap/soap.c 2013-11-15 17:21:04.504212497 +0100 @@ -2702,6 +2702,7 @@ SOAP_GLOBAL(features) = 0; } + zend_try { if (sdl != NULL) { fn = get_function(sdl, function); if (fn != NULL) { @@ -2811,6 +2812,9 @@ MAKE_COPY_ZVAL(&return_value, exception); zend_throw_exception_object(exception TSRMLS_CC); } + } zend_catch { + _bailout = 1; + } zend_end_try(); if (SOAP_GLOBAL(encoding) != NULL) { xmlCharEncCloseFunc(SOAP_GLOBAL(encoding)); @@ -2820,6 +2824,8 @@ SOAP_GLOBAL(class_map) = old_class_map; SOAP_GLOBAL(encoding) = old_encoding; SOAP_GLOBAL(sdl) = old_sdl; + if (_bailout) + zend_bailout(); SOAP_CLIENT_END_CODE(); } ------------------------------------------------------------------------ [2013-11-18 12:52:46] martin dot koegler at brz dot gv dot at Description: ------------ do_soap_call (ext/soap/soap.c) saves the values of SOAP_GLOBAL(typemap) (and other variables) and overrides them. After doing its work, it restores the old values. If the code in between invokes zend_bailout (eg. because of an error/exception), the zend_bailout is catched after the restore of the values. So SOAP_GLOBAL(typemap) is not restored. The remaining code executes using a invalid, potential freed typemap. Actual result: -------------- Segfault ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=66112&edit=1

« previous php.bugs (#182812) next »