Sec Bug->Bug #66060 [Csd]: Heap buffer over-read in DateInterval

From: Date: Tue, 07 Jan 2014 15:37:30 +0000
Subject: Sec Bug->Bug #66060 [Csd]: Heap buffer over-read in DateInterval
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-183627@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=66060&edit=1 ID: 66060 Updated by: remi@php.net Reported by: jutaky at polarptr dot com Summary: Heap buffer over-read in DateInterval Status: Closed -Type: Security +Type: Bug Package: Reproducible crash Operating System: Linux PHP Version: master-Git-2013-11-08 (Git) Assigned To: remi Block user comment: N Private report: Y Previous Comments: ------------------------------------------------------------------------ [2013-11-27 10:19:19] remi@php.net The fix for this bug has been committed. Snapshots of the sources are packaged every three hours; this change will be in the next snapshot. You can grab the snapshot at http://snaps.php.net/. For Windows: http://windows.php.net/snapshots/ Thank you for the report, and for helping us make PHP better. Fix applied ------------------------------------------------------------------------ [2013-11-08 17:12:25] remi@php.net The following patch has been added/updated: Patch Name: proposal.patch Revision: 1383930745 URL: https://bugs.php.net/patch-display.php?bug=66060&patch=proposal.patch&revision=1383930745 ------------------------------------------------------------------------ [2013-11-08 17:11:49] remi@php.net The following patch has been added/updated: Patch Name: proposal.path Revision: 1383930709 URL: https://bugs.php.net/patch-display.php?bug=66060&patch=proposal.path&revision=1383930709 ------------------------------------------------------------------------ [2013-11-08 15:00:50] jutaky at polarptr dot com CVE-2013-6712 has been assigned to this issue. -- Juha Kylmänen Research Assistant, OUSPG ------------------------------------------------------------------------ [2013-11-08 10:29:02] jutaky at polarptr dot com Description: ------------ Heap buffer over-read in DateInterval. Versions affected, at least: 5.5.3 and 5.6.0-dev (master-git) Built with AddressSanitizer, prefix and debug. Test script: --------------- <?php new DateInterval('P170141183460469231731687303715884105729D'); ?> Actual result: -------------- ==6428== ERROR: AddressSanitizer: heap-buffer-overflow on address 0x600800019eba at pc 0x4bb89c bp 0x7fff79056660 sp 0x7fff79056658 READ of size 1 at 0x600800019eba thread T0 #0 0x4bb89b in scan /php-src/ext/date/lib/parse_iso_intervals.re:351 #1 0x4bf896 in timelib_strtointerval /php-src/ext/date/lib/parse_iso_intervals.re:485 (discriminator 1) #2 0x44461e in date_interval_initialize /php-src/ext/date/php_date.c:3984 #3 0x4467ff in zim_DateInterval___construct /php-src/ext/date/php_date.c:4147 #4 0xdfa974 in zend_do_fcall_common_helper_SPEC /php-src/Zend/zend_vm_execute.h:554 #5 0xdfd205 in ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER /php-src/Zend/zend_vm_execute.h:689 #6 0xdf61f6 in execute_ex /php-src/Zend/zend_vm_execute.h:363 #7 0xdf7b3f in zend_execute /php-src/Zend/zend_vm_execute.h:388 #8 0xd374d9 in zend_execute_scripts /php-src/Zend/zend.c:1334 #9 0xbb4c3e in php_execute_script /php-src/main/main.c:2490 #10 0x10829ae in do_cli /php-src/sapi/cli/php_cli.c:994 #11 0x1085285 in main /php-src/sapi/cli/php_cli.c:1378 #12 0x7fbb22be5bc4 in __libc_start_main ??:? #13 0x421498 in _start ??:? 0x600800019eba is located 0 bytes to the right of 42-byte region [0x600800019e90,0x600800019eba) allocated by thread T0 here: #0 0x7fbb24276625 in ?? ??:0 #1 0x4b9da2 in timelib_string /php-src/ext/date/lib/parse_iso_intervals.re:125 #2 0x4bb442 in scan /php-src/ext/date/lib/parse_iso_intervals.re:320 #3 0x4bf896 in timelib_strtointerval /php-src/ext/date/lib/parse_iso_intervals.re:485 (discriminator 1) #4 0x44461e in date_interval_initialize /php-src/ext/date/php_date.c:3984 #5 0x4467ff in zim_DateInterval___construct /php-src/ext/date/php_date.c:4147 #6 0xdfa974 in zend_do_fcall_common_helper_SPEC /php-src/Zend/zend_vm_execute.h:554 #7 0xdfd205 in ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER /php-src/Zend/zend_vm_execute.h:689 #8 0xdf61f6 in execute_ex /php-src/Zend/zend_vm_execute.h:363 #9 0xdf7b3f in zend_execute /php-src/Zend/zend_vm_execute.h:388 #10 0xd374d9 in zend_execute_scripts /php-src/Zend/zend.c:1334 #11 0xbb4c3e in php_execute_script /php-src/main/main.c:2490 #12 0x10829ae in do_cli /php-src/sapi/cli/php_cli.c:994 #13 0x1085285 in main /php-src/sapi/cli/php_cli.c:1378 #14 0x7fbb22be5bc4 in __libc_start_main ??:? ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=66060&edit=1

« previous php.bugs (#183627) next »