Bug #68618 [NEW]: out of bounds read crashes php-cgi

From: Date: Wed, 17 Dec 2014 21:24:21 +0000
Subject: Bug #68618 [NEW]: out of bounds read crashes php-cgi
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-189103@lists.php.net to get a copy of this message
From: brian dot carpenter at gmail dot com Operating system: Debian 7 PHP version: master-Git-2014-12-17 (Git) Package: Reproducible crash Bug Type: Bug Bug description:out of bounds read crashes php-cgi Description: ------------ I cloned the php git repo on 12/16/2014 and built from source using the afl-gcc compiler: CC=/path/to/afl-gcc ./configure AFL_HARDEN=1 make PHP 7.0.0-dev (cgi-fcgi) (built: Dec 16 2014 14:07:45) Copyright (c) 1997-2014 The PHP Group Zend Engine v3.0.0-dev, Copyright (c) 1998-2014 Zend Technologies While fuzzing the php-cgi binary, I found that a one byte file containing # and no newline causes php-cgi to segfault. printf "#" >crashme.php ./php-cgi crashme.php Segmentation fault I talked with the author of afl-fuzz to make sure there wasn't some pointer weirdness happening as a result of compiling this with afl-gcc and he says it looks like an out of bounds read, probably not exploitable, but might could disclose server memory, but anyone that can upload php scripts can do far worse. I have not tried exploiting this via a browser with XSS or anything fancy yet, just passing this via the command line in a Debian VM. I can provide a core dump or any other information that is needed. Expected result: ---------------- php-cgi should fail gracefully, not segfault. Actual result: -------------- ==61759== Invalid read of size 1 ==61759== at 0x4575B0: main (cgi_main.c:2460) ==61759== Address 0x4024000 is not stack'd, malloc'd or (recently) free'd ==61759== ==61759== ==61759== Process terminating with default action of signal 11 (SIGSEGV) ==61759== Access not within mapped region at address 0x4024000 ==61759== at 0x4575B0: main (cgi_main.c:2460) ==61759== If you believe this happened as a result of a stack ==61759== overflow in your program's main thread (unlikely but ==61759== possible), you can try to increase the size of the ==61759== main thread stack using the --main-stacksize= flag. ==61759== The main thread stack size used in this run was 8388608. Segmentation fault -- Edit bug report at https://bugs.php.net/bug.php?id=68618&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=68618&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=68618&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=68618&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=68618&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=68618&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=68618&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=68618&r=needscript Try newer version: https://bugs.php.net/fix.php?id=68618&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=68618&r=support Expected behavior: https://bugs.php.net/fix.php?id=68618&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=68618&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=68618&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=68618&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=68618&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=68618&r=dst IIS Stability: https://bugs.php.net/fix.php?id=68618&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=68618&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=68618&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=68618&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=68618&r=mysqlcfg

« previous php.bugs (#189103) next »