Sec Bug->Bug #66060 [Csd]: Heap buffer over-read in DateInterval
| From: | remi@php.net | Date: | Tue, 07 Jan 2014 15:37:30 +0000 |
| Subject: | Sec Bug->Bug #66060 [Csd]: Heap buffer over-read in DateInterval | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-183627@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=66060&edit=1
ID: 66060
Updated by: remi@php.net
Reported by: jutaky at polarptr dot com
Summary: Heap buffer over-read in DateInterval
Status: Closed
-Type: Security
+Type: Bug
Package: Reproducible crash
Operating System: Linux
PHP Version: master-Git-2013-11-08 (Git)
Assigned To: remi
Block user comment: N
Private report: Y
Previous Comments:
------------------------------------------------------------------------
[2013-11-27 10:19:19] remi@php.net
The fix for this bug has been committed.
Snapshots of the sources are packaged every three hours; this change
will be in the next snapshot. You can grab the snapshot at
http://snaps.php.net/.
For Windows:
http://windows.php.net/snapshots/
Thank you for the report, and for helping us make PHP better.
Fix applied
------------------------------------------------------------------------
[2013-11-08 17:12:25] remi@php.net
The following patch has been added/updated:
Patch Name: proposal.patch
Revision: 1383930745
URL: https://bugs.php.net/patch-display.php?bug=66060&patch=proposal.patch&revision=1383930745
------------------------------------------------------------------------
[2013-11-08 17:11:49] remi@php.net
The following patch has been added/updated:
Patch Name: proposal.path
Revision: 1383930709
URL: https://bugs.php.net/patch-display.php?bug=66060&patch=proposal.path&revision=1383930709
------------------------------------------------------------------------
[2013-11-08 15:00:50] jutaky at polarptr dot com
CVE-2013-6712 has been assigned to this issue.
--
Juha Kylmänen
Research Assistant, OUSPG
------------------------------------------------------------------------
[2013-11-08 10:29:02] jutaky at polarptr dot com
Description:
------------
Heap buffer over-read in DateInterval.
Versions affected, at least: 5.5.3 and 5.6.0-dev (master-git)
Built with AddressSanitizer, prefix and debug.
Test script:
---------------
<?php new DateInterval('P170141183460469231731687303715884105729D'); ?>
Actual result:
--------------
==6428== ERROR: AddressSanitizer: heap-buffer-overflow on address 0x600800019eba at pc 0x4bb89c bp
0x7fff79056660 sp 0x7fff79056658
READ of size 1 at 0x600800019eba thread T0
#0 0x4bb89b in scan /php-src/ext/date/lib/parse_iso_intervals.re:351
#1 0x4bf896 in timelib_strtointerval /php-src/ext/date/lib/parse_iso_intervals.re:485
(discriminator 1)
#2 0x44461e in date_interval_initialize /php-src/ext/date/php_date.c:3984
#3 0x4467ff in zim_DateInterval___construct /php-src/ext/date/php_date.c:4147
#4 0xdfa974 in zend_do_fcall_common_helper_SPEC /php-src/Zend/zend_vm_execute.h:554
#5 0xdfd205 in ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER /php-src/Zend/zend_vm_execute.h:689
#6 0xdf61f6 in execute_ex /php-src/Zend/zend_vm_execute.h:363
#7 0xdf7b3f in zend_execute /php-src/Zend/zend_vm_execute.h:388
#8 0xd374d9 in zend_execute_scripts /php-src/Zend/zend.c:1334
#9 0xbb4c3e in php_execute_script /php-src/main/main.c:2490
#10 0x10829ae in do_cli /php-src/sapi/cli/php_cli.c:994
#11 0x1085285 in main /php-src/sapi/cli/php_cli.c:1378
#12 0x7fbb22be5bc4 in __libc_start_main ??:?
#13 0x421498 in _start ??:?
0x600800019eba is located 0 bytes to the right of 42-byte region [0x600800019e90,0x600800019eba)
allocated by thread T0 here:
#0 0x7fbb24276625 in ?? ??:0
#1 0x4b9da2 in timelib_string /php-src/ext/date/lib/parse_iso_intervals.re:125
#2 0x4bb442 in scan /php-src/ext/date/lib/parse_iso_intervals.re:320
#3 0x4bf896 in timelib_strtointerval /php-src/ext/date/lib/parse_iso_intervals.re:485
(discriminator 1)
#4 0x44461e in date_interval_initialize /php-src/ext/date/php_date.c:3984
#5 0x4467ff in zim_DateInterval___construct /php-src/ext/date/php_date.c:4147
#6 0xdfa974 in zend_do_fcall_common_helper_SPEC /php-src/Zend/zend_vm_execute.h:554
#7 0xdfd205 in ZEND_DO_FCALL_BY_NAME_SPEC_HANDLER /php-src/Zend/zend_vm_execute.h:689
#8 0xdf61f6 in execute_ex /php-src/Zend/zend_vm_execute.h:363
#9 0xdf7b3f in zend_execute /php-src/Zend/zend_vm_execute.h:388
#10 0xd374d9 in zend_execute_scripts /php-src/Zend/zend.c:1334
#11 0xbb4c3e in php_execute_script /php-src/main/main.c:2490
#12 0x10829ae in do_cli /php-src/sapi/cli/php_cli.c:994
#13 0x1085285 in main /php-src/sapi/cli/php_cli.c:1378
#14 0x7fbb22be5bc4 in __libc_start_main ??:?
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=66060&edit=1