Bug #68996 [Opn]: Invalid free of CG(interned_empty_string)
Edit report at https://bugs.php.net/bug.php?id=68996&edit=1
ID: 68996
User updated by: manuel-php at mausz dot at
Reported by: manuel-php at mausz dot at
Summary: Invalid free of CG(interned_empty_string)
Status: Open
Type: Bug
Package: Reproducible crash
PHP Version: 5.6.6RC1
Block user comment: N
Private report: N
New Comment:
PR: https://github.com/php/php-src/pull/1060
Previous Comments:
------------------------------------------------------------------------
[2015-02-06 15:58:17] manuel-php at mausz dot at
Description:
------------
If php_escape_html_entities fails CG(interned_empty_string) will be freed:
* If interned strings are enabled (default) STR_EMPTY_ALLOC is an alias for
CG(interned_empty_string)
see https://github.com/php/php-src/blob/PHP-5.6/Zend/zend.h#L682
* php_escape_html_entities_ex returns STR_EMPTY_ALLOC in case of failure
see https://github.com/php/php-src/blob/PHP-5.6/ext/standard/html.c#L1307
* php_escape_html_entities is used in php_verror if display_errors is enabled
see https://github.com/php/php-src/blob/PHP-5.6/main/main.c#L848
* Thus CG(interned_empty_string) gets freed
see https://github.com/php/php-src/blob/PHP-5.6/main/main.c#L921
This issue is even worse when opcache is enabled.
Sample script:
fopen("\xfc\x63", "r");
https://github.com/php/php-src/blob/PHP-5.6/ext/wddx/wddx.c#L408:
wddx_serialize_value("\xfc\x63");
https://github.com/php/php-src/blob/PHP-5.6/ext/wddx/wddx.c#L633:
wddx_serialize_value([ "\xfc\x63" => "foo" ]);
https://github.com/php/php-src/blob/PHP-5.6/ext/soap/soap.c#L3997
https://github.com/php/php-src/blob/PHP-5.6/ext/soap/soap.c#L4022
(new SoapServer(NULL, [ "location" => "http://foo", "uri" => "http://foo" ]))->fault("\xfc\x63", "foo");
No issues (imho):
https://github.com/php/php-src/blob/PHP-5.6/main/main.c#L790
https://github.com/php/php-src/blob/PHP-5.6/sapi/fpm/fpm/fpm_status.c#L421
https://github.com/php/php-src/blob/PHP-5.6/sapi/cli/php_cli_server.c#L1929
php_escape_html_entities calls in https://github.com/php/php-src/blob/PHP-5.6/info/info.c
are safe too
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=68996&edit=1
Thread (5 messages)