Bug #67539 [Csd->Asn]: ArrayIterator use-after-free due to object change during sorting
| From: | research at insighti dot org | Date: | Tue, 15 Jul 2014 14:42:57 +0000 |
| Subject: | Bug #67539 [Csd->Asn]: ArrayIterator use-after-free due to object change during sorting | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-186635@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=67539&edit=1
ID: 67539
User updated by: research at insighti dot org
Reported by: research at insighti dot org
Summary: ArrayIterator use-after-free due to object change
during sorting
-Status: Closed
+Status: Assigned
Type: Bug
Package: SPL related
Operating System: *
PHP Version: Irrelevant
Block user comment: N
Private report: N
New Comment:
Please use the assigned CVE-2014-4698. 5.5.15-RC1 is now out and CVE is missing.
Previous Comments:
------------------------------------------------------------------------
[2014-07-07 15:22:04] dmitry@php.net
Automatic comment on behalf of laruence
Revision: http://git.php.net/?p=php-src.git;a=commit;h=22882a9d89712ff2b6ebc20a689a89452bba4dcd
Log: Fixed bug #67539 (ArrayIterator use-after-free due to object change during sorting)
------------------------------------------------------------------------
[2014-07-05 12:09:38] research at insighti dot org
As per the other reported bug, same applies for this one:
Please use CVE-2014-4698, the bug is in fact exploitable - not sure why was it made public before
release of a patched version.
It's not remotely exploitable, however, shared environments relying on PHP security features
(open_basedir, safe_mode in older PHPs, disable_functions and similar) are affected. We're
ready to provide PoC is needed.
------------------------------------------------------------------------
[2014-07-03 22:45:05] research at insighti dot org
Please use CVE-2014-4698 for this issue.
------------------------------------------------------------------------
[2014-07-02 09:58:57] laruence@php.net
Automatic comment on behalf of laruence
Revision: http://git.php.net/?p=php-src.git;a=commit;h=22882a9d89712ff2b6ebc20a689a89452bba4dcd
Log: Fixed bug #67539 (ArrayIterator use-after-free due to object change during sorting)
------------------------------------------------------------------------
[2014-06-29 15:35:47] research at insighti dot org
The following patch fixes the issue. Bug tracker does not allow us to submit a patch file to a
private report for some reason.
diff --git a/ext/spl/spl_array.c b/ext/spl/spl_array.c
index c38065f..a75f9ca 100644
--- a/ext/spl/spl_array.c
+++ b/ext/spl/spl_array.c
@@ -1737,6 +1737,12 @@ SPL_METHOD(Array, unserialize)
{
spl_array_object *intern = (spl_array_object*)zend_object_store_get_object(getThis() TSRMLS_CC);
+ HashTable *htable = spl_array_get_hash_table(intern, 0 TSRMLS_CC);
+ if (htable->nApplyCount > 0) {
+ zend_error(E_WARNING, "Modification of ArrayObject during sorting is prohibited");
+ return;
+ }
+
char *buf;
int buf_len;
const unsigned char *p, *s;
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=67539
--
Edit this bug report at https://bugs.php.net/bug.php?id=67539&edit=1