Bug #68618 [NEW]: out of bounds read crashes php-cgi
| From: | brian dot carpenter at gmail dot com | Date: | Wed, 17 Dec 2014 21:24:21 +0000 |
| Subject: | Bug #68618 [NEW]: out of bounds read crashes php-cgi | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-189103@lists.php.net to get a copy of this message | ||
From: brian dot carpenter at gmail dot com
Operating system: Debian 7
PHP version: master-Git-2014-12-17 (Git)
Package: Reproducible crash
Bug Type: Bug
Bug description:out of bounds read crashes php-cgi
Description:
------------
I cloned the php git repo on 12/16/2014 and built from source using the
afl-gcc compiler:
CC=/path/to/afl-gcc ./configure
AFL_HARDEN=1 make
PHP 7.0.0-dev (cgi-fcgi) (built: Dec 16 2014 14:07:45)
Copyright (c) 1997-2014 The PHP Group
Zend Engine v3.0.0-dev, Copyright (c) 1998-2014 Zend Technologies
While fuzzing the php-cgi binary, I found that a one byte file
containing # and no newline causes php-cgi to segfault.
printf "#" >crashme.php
./php-cgi crashme.php
Segmentation fault
I talked with the author of afl-fuzz to make sure there wasn't some
pointer weirdness happening as a result of compiling this with afl-gcc
and he says it looks like an out of bounds read, probably not
exploitable, but might could disclose server memory, but anyone that can
upload php scripts can do far worse.
I have not tried exploiting this via a browser with XSS or anything
fancy yet, just passing this via the command line in a Debian VM. I can
provide a core dump or any other information that is needed.
Expected result:
----------------
php-cgi should fail gracefully, not segfault.
Actual result:
--------------
==61759== Invalid read of size 1
==61759== at 0x4575B0: main (cgi_main.c:2460)
==61759== Address 0x4024000 is not stack'd, malloc'd or (recently)
free'd
==61759==
==61759==
==61759== Process terminating with default action of signal 11
(SIGSEGV)
==61759== Access not within mapped region at address 0x4024000
==61759== at 0x4575B0: main (cgi_main.c:2460)
==61759== If you believe this happened as a result of a stack
==61759== overflow in your program's main thread (unlikely but
==61759== possible), you can try to increase the size of the
==61759== main thread stack using the --main-stacksize= flag.
==61759== The main thread stack size used in this run was 8388608.
Segmentation fault
--
Edit bug report at https://bugs.php.net/bug.php?id=68618&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=68618&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=68618&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=68618&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=68618&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=68618&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=68618&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=68618&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=68618&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=68618&r=support
Expected behavior: https://bugs.php.net/fix.php?id=68618&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=68618&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=68618&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=68618&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=68618&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=68618&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=68618&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=68618&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=68618&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=68618&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=68618&r=mysqlcfg