Bug #70430 [Fbk]: Stack buffer overflow in zend_language_parser()

From: Date: Mon, 12 Oct 2015 20:08:06 +0000
Subject: Bug #70430 [Fbk]: Stack buffer overflow in zend_language_parser()
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-196564@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70430&edit=1 ID: 70430 Updated by: nikic@php.net Reported by: s dot paraschoudis at gmail dot com Summary: Stack buffer overflow in zend_language_parser() Status: Feedback Type: Bug Package: Reproducible crash Operating System: Ubuntu 14.04 x32 PHP Version: 7.0.0RC2 -Assigned To: +Assigned To: nikic Block user comment: N Private report: N New Comment: I can't repro this myself, could you please check whether the patch at https://github.com/php/php-src/pull/1571 fixes the issue? Previous Comments: ------------------------------------------------------------------------ [2015-10-11 14:14:24] nikic@php.net Regardless of whether it crashes or not, our yytnamerr implementation is clearly bogus. The !yyerr branch [1] simply returns yystrlen(yystr), which does not account for the additional information we show in the error message. [1]: http://lxr.php.net/xref/PHP_TRUNK/Zend/zend_language_parser.y#1281 ------------------------------------------------------------------------ [2015-10-11 14:04:22] s dot paraschoudis at gmail dot com Alright, looks like it doesn't crash anymore latest php (rc4) with a non-asan build, but trying with an asan one you should catch it. ------------------------------------------------------------------------ [2015-10-11 13:54:08] s dot paraschoudis at gmail dot com Hi, just tested on RC4 release, it still crashes it.. I have more test cases that trigger it but you should be able to reproduce it.. ------------------------------------------------------------------------ [2015-10-11 13:43:32] felipe@php.net I can't reproduce it. Can you try again? ------------------------------------------------------------------------ [2015-09-04 15:42:20] s dot paraschoudis at gmail dot com Update: I can reproduce it on 64bit, here's the output: ================================================================= ==89897==ERROR: AddressSanitizer: stack-buffer-overflow on address 0x7fffa164cff0 at pc 0x0000018bdba5 bp 0x7fffa164c390 sp 0x7fffa164c388 WRITE of size 1 at 0x7fffa164cff0 thread T0 #0 0x18bdba4 in yysyntax_error /home/symeon/Desktop/php-7.0.0RC2/Zend/zend_language_parser.c:3256:18 #1 0x18bb113 in zendparse /home/symeon/Desktop/php-7.0.0RC2/Zend/zend_language_parser.c:6833:33 #2 0x18c7c02 in compile_file /home/symeon/Desktop/php-7.0.0RC2/Zend/zend_language_scanner.l:591:8 #3 0x114cdfa in phar_compile_file /home/symeon/Desktop/php-7.0.0RC2/ext/phar/phar.c:3311:9 #4 0x1a91e46 in zend_execute_scripts /home/symeon/Desktop/php-7.0.0RC2/Zend/zend.c:1394:14 #5 0x1798ef4 in php_execute_script /home/symeon/Desktop/php-7.0.0RC2/main/main.c:2471:14 #6 0x1f1f06e in do_cli /home/symeon/Desktop/php-7.0.0RC2/sapi/cli/php_cli.c:971:5 #7 0x1f1ab3e in main /home/symeon/Desktop/php-7.0.0RC2/sapi/cli/php_cli.c:1342:18 #8 0x7fd6fcae8ec4 in __libc_start_main /build/buildd/eglibc-2.19/csu/libc-start.c:287 #9 0x45e355 in _start (/home/symeon/Desktop/php-7.0.0RC2/sapi/cli/php+0x45e355) Address 0x7fffa164cff0 is located in stack of thread T0 at offset 2416 in frame #0 0x18a5b4f in zendparse /home/symeon/Desktop/php-7.0.0RC2/Zend/zend_language_parser.c:4023 This frame has 10 object(s): [32, 40) 'yylval' [64, 464) 'yyssa' [528, 2128) 'yyvsa' [2256, 2264) 'yyval' [2288, 2416) 'yymsgbuf' <== Memory access at offset 2416 overflows this variable [2448, 2456) 'yymsg' [2480, 2488) 'yymsg_alloc' [2512, 2528) 'zv' [2544, 2560) 'zv1105' [2576, 2592) 'zv1875' ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=70430 -- Edit this bug report at https://bugs.php.net/bug.php?id=70430&edit=1

« previous php.bugs (#196564) next »