Bug #67338 [Opn->Csd]: Data from Faulting Address controls subsequent Write Address
| From: | jigsaw0658 at gmail dot com | Date: | Thu, 30 Oct 2014 09:36:19 +0000 |
| Subject: | Bug #67338 [Opn->Csd]: Data from Faulting Address controls subsequent Write Address | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-188373@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=67338&edit=1
ID: 67338
User updated by: jigsaw0658 at gmail dot com
Reported by: jigsaw0658 at gmail dot com
Summary: Data from Faulting Address controls subsequent Write
Address
-Status: Open
+Status: Closed
Type: Bug
Package: Apache2 related
Operating System: Windows 7_64bit
PHP Version: Irrelevant
Block user comment: N
Private report: N
New Comment:
Closed
Previous Comments:
------------------------------------------------------------------------
[2014-05-30 20:38:07] jigsaw0658 at gmail dot com
Hi,
I didn't get a reply for my latest comment.
------------------------------------------------------------------------
[2014-05-27 13:24:55] jigsaw0658 at gmail dot com
Hi,
can you explain please why it's not a security issue because the analysis show that the bug can
be probably exploitable based on the stack trace and the attempt of reading from address 05883050.
In addition if we are able to overwrite/corrupt the pointer it can be exploitable surely.
i'll provide soon a crash dump so u can investigate further.
Regards,
------------------------------------------------------------------------
[2014-05-27 05:25:38] stas@php.net
Doesn't look like a security issue.
------------------------------------------------------------------------
[2014-05-25 14:22:53] jigsaw0658 at gmail dot com
Hi, let me explain how i detected this behavior :
the first time i tested the script it triggers the crash of Apache service httpd.exe until i restart
the service again. This behavior occurred 3 times while executing the same script but later i
wasn't able to reproduce it, anyway here is the script i used :
<?php
session_start();
set_time_limit(5000);
$code = md5(uniqid(rand(), true));
$HTTP['http']['method'] = 'GET';
$HTTP['http']['follow_location'] = 0;
$HTTP['http']['header'] = "Host: host.com\r\n";
$HTTP['http']['header'] .= "Referer: http://host.com/\r\n";
$HTTP['http']['header'] = "Cookie:
COOKIE=u275gfdjphn0rr721avhgcps82; screenWidth=1366\r\n";
$link = "http://example.com/index.php?Page=Login&Action=ConfirmCode&user=1&code=$code";
$context = stream_context_create($HTTP);
$string = file_get_contents($link, false, $context);
$file = "log1.txt";
file_put_contents($file,$string);
function RightLine($str,$r)
{
$str = 'Fill in the form to generate a new password. An email will be sent to you containing a
link which you must click to confirm your password change.';
$matches = array();
$file = "log1.txt";
$handle = fopen($file, "r");
if ($handle)
{
while (!feof($handle))
{
$buffer = fgets($handle);
if(strpos($buffer, $str) == TRUE)
$matches[] = $buffer;
}
fclose($handle);
}
$res = substr($matches[0],$r = 0);
return $res;
}
do
{
RightLine($str,$r);
}while(RightLine($str,$r) == $str);
echo $code;
?>
------------------------------------------------------------------------
[2014-05-25 08:52:27] pajoye@php.net
Thanks for the report.
Could you attach the test.php script please?
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=67338
--
Edit this bug report at https://bugs.php.net/bug.php?id=67338&edit=1