Bug #67338 [Opn->Csd]: Data from Faulting Address controls subsequent Write Address

From: Date: Thu, 30 Oct 2014 09:36:19 +0000
Subject: Bug #67338 [Opn->Csd]: Data from Faulting Address controls subsequent Write Address
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-188373@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=67338&edit=1 ID: 67338 User updated by: jigsaw0658 at gmail dot com Reported by: jigsaw0658 at gmail dot com Summary: Data from Faulting Address controls subsequent Write Address -Status: Open +Status: Closed Type: Bug Package: Apache2 related Operating System: Windows 7_64bit PHP Version: Irrelevant Block user comment: N Private report: N New Comment: Closed Previous Comments: ------------------------------------------------------------------------ [2014-05-30 20:38:07] jigsaw0658 at gmail dot com Hi, I didn't get a reply for my latest comment. ------------------------------------------------------------------------ [2014-05-27 13:24:55] jigsaw0658 at gmail dot com Hi, can you explain please why it's not a security issue because the analysis show that the bug can be probably exploitable based on the stack trace and the attempt of reading from address 05883050. In addition if we are able to overwrite/corrupt the pointer it can be exploitable surely. i'll provide soon a crash dump so u can investigate further. Regards, ------------------------------------------------------------------------ [2014-05-27 05:25:38] stas@php.net Doesn't look like a security issue. ------------------------------------------------------------------------ [2014-05-25 14:22:53] jigsaw0658 at gmail dot com Hi, let me explain how i detected this behavior : the first time i tested the script it triggers the crash of Apache service httpd.exe until i restart the service again. This behavior occurred 3 times while executing the same script but later i wasn't able to reproduce it, anyway here is the script i used : <?php session_start(); set_time_limit(5000); $code = md5(uniqid(rand(), true)); $HTTP['http']['method'] = 'GET'; $HTTP['http']['follow_location'] = 0; $HTTP['http']['header'] = "Host: host.com\r\n"; $HTTP['http']['header'] .= "Referer: http://host.com/\r\n"; $HTTP['http']['header'] = "Cookie: COOKIE=u275gfdjphn0rr721avhgcps82; screenWidth=1366\r\n"; $link = "http://example.com/index.php?Page=Login&Action=ConfirmCode&user=1&code=$code"; $context = stream_context_create($HTTP); $string = file_get_contents($link, false, $context); $file = "log1.txt"; file_put_contents($file,$string); function RightLine($str,$r) { $str = 'Fill in the form to generate a new password. An email will be sent to you containing a link which you must click to confirm your password change.'; $matches = array(); $file = "log1.txt"; $handle = fopen($file, "r"); if ($handle) { while (!feof($handle)) { $buffer = fgets($handle); if(strpos($buffer, $str) == TRUE) $matches[] = $buffer; } fclose($handle); } $res = substr($matches[0],$r = 0); return $res; } do { RightLine($str,$r); }while(RightLine($str,$r) == $str); echo $code; ?> ------------------------------------------------------------------------ [2014-05-25 08:52:27] pajoye@php.net Thanks for the report. Could you attach the test.php script please? ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=67338 -- Edit this bug report at https://bugs.php.net/bug.php?id=67338&edit=1

« previous php.bugs (#188373) next »