Bug #70430 [Fbk]: Stack buffer overflow in zend_language_parser()
| From: | nikic@php.net | Date: | Mon, 12 Oct 2015 20:08:06 +0000 |
| Subject: | Bug #70430 [Fbk]: Stack buffer overflow in zend_language_parser() | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-196564@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=70430&edit=1
ID: 70430
Updated by: nikic@php.net
Reported by: s dot paraschoudis at gmail dot com
Summary: Stack buffer overflow in zend_language_parser()
Status: Feedback
Type: Bug
Package: Reproducible crash
Operating System: Ubuntu 14.04 x32
PHP Version: 7.0.0RC2
-Assigned To:
+Assigned To: nikic
Block user comment: N
Private report: N
New Comment:
I can't repro this myself, could you please check whether the patch at https://github.com/php/php-src/pull/1571 fixes
the issue?
Previous Comments:
------------------------------------------------------------------------
[2015-10-11 14:14:24] nikic@php.net
Regardless of whether it crashes or not, our yytnamerr implementation is clearly bogus. The !yyerr
branch [1] simply returns yystrlen(yystr), which does not account for the additional information we
show in the error message.
[1]: http://lxr.php.net/xref/PHP_TRUNK/Zend/zend_language_parser.y#1281
------------------------------------------------------------------------
[2015-10-11 14:04:22] s dot paraschoudis at gmail dot com
Alright, looks like it doesn't crash anymore latest php (rc4) with a non-asan build,
but trying with an asan one you should catch it.
------------------------------------------------------------------------
[2015-10-11 13:54:08] s dot paraschoudis at gmail dot com
Hi, just tested on RC4 release, it still crashes it..
I have more test cases that trigger it but you should be able to reproduce it..
------------------------------------------------------------------------
[2015-10-11 13:43:32] felipe@php.net
I can't reproduce it. Can you try again?
------------------------------------------------------------------------
[2015-09-04 15:42:20] s dot paraschoudis at gmail dot com
Update: I can reproduce it on 64bit, here's the output:
=================================================================
==89897==ERROR: AddressSanitizer: stack-buffer-overflow on address 0x7fffa164cff0 at pc
0x0000018bdba5 bp 0x7fffa164c390 sp 0x7fffa164c388
WRITE of size 1 at 0x7fffa164cff0 thread T0
#0 0x18bdba4 in yysyntax_error
/home/symeon/Desktop/php-7.0.0RC2/Zend/zend_language_parser.c:3256:18
#1 0x18bb113 in zendparse /home/symeon/Desktop/php-7.0.0RC2/Zend/zend_language_parser.c:6833:33
#2 0x18c7c02 in compile_file
/home/symeon/Desktop/php-7.0.0RC2/Zend/zend_language_scanner.l:591:8
#3 0x114cdfa in phar_compile_file /home/symeon/Desktop/php-7.0.0RC2/ext/phar/phar.c:3311:9
#4 0x1a91e46 in zend_execute_scripts /home/symeon/Desktop/php-7.0.0RC2/Zend/zend.c:1394:14
#5 0x1798ef4 in php_execute_script /home/symeon/Desktop/php-7.0.0RC2/main/main.c:2471:14
#6 0x1f1f06e in do_cli /home/symeon/Desktop/php-7.0.0RC2/sapi/cli/php_cli.c:971:5
#7 0x1f1ab3e in main /home/symeon/Desktop/php-7.0.0RC2/sapi/cli/php_cli.c:1342:18
#8 0x7fd6fcae8ec4 in __libc_start_main /build/buildd/eglibc-2.19/csu/libc-start.c:287
#9 0x45e355 in _start (/home/symeon/Desktop/php-7.0.0RC2/sapi/cli/php+0x45e355)
Address 0x7fffa164cff0 is located in stack of thread T0 at offset 2416 in frame
#0 0x18a5b4f in zendparse /home/symeon/Desktop/php-7.0.0RC2/Zend/zend_language_parser.c:4023
This frame has 10 object(s):
[32, 40) 'yylval'
[64, 464) 'yyssa'
[528, 2128) 'yyvsa'
[2256, 2264) 'yyval'
[2288, 2416) 'yymsgbuf' <== Memory access at offset 2416 overflows this variable
[2448, 2456) 'yymsg'
[2480, 2488) 'yymsg_alloc'
[2512, 2528) 'zv'
[2544, 2560) 'zv1105'
[2576, 2592) 'zv1875'
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=70430
--
Edit this bug report at https://bugs.php.net/bug.php?id=70430&edit=1