Bug #70430 [Fbk->Asn]: Stack buffer overflow in zend_language_parser()

From: Date: Mon, 12 Oct 2015 21:24:43 +0000
Subject: Bug #70430 [Fbk->Asn]: Stack buffer overflow in zend_language_parser()
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-196570@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70430&edit=1 ID: 70430 User updated by: s dot paraschoudis at gmail dot com Reported by: s dot paraschoudis at gmail dot com Summary: Stack buffer overflow in zend_language_parser() -Status: Feedback +Status: Assigned Type: Bug Package: Reproducible crash Operating System: Ubuntu 14.04 x32 PHP Version: 7.0.0RC2 Assigned To: nikic Block user comment: N Private report: N New Comment: Hi, it looks like it's still there but this time on line zend_language_parser.c:3268 while ((*yyp = *yyformat) != '\0') <-- according to asan here is where the overflow occurs. Output: ==37540==ERROR: AddressSanitizer: stack-buffer-overflow on address 0x7fff12f060d0 at pc 0x000001227dbd bp 0x7fff12f05490 sp 0x7fff12f05488 WRITE of size 1 at 0x7fff12f060d0 thread T0 #0 0x1227dbc in yysyntax_error /home/symeon/Desktop/php-7.0_fixed/Zend/zend_language_parser.c:3268:18 #1 0x122636a in zendparse /home/symeon/Desktop/php-7.0_fixed/Zend/zend_language_parser.c:6845:33 #2 0x122ed0c in compile_file /home/symeon/Desktop/php-7.0_fixed/Zend/zend_language_scanner.l:591:8 #3 0xd46a25 in phar_compile_file /home/symeon/Desktop/php-7.0_fixed/ext/phar/phar.c:3311:9 #4 0x13650ea in zend_execute_scripts /home/symeon/Desktop/php-7.0_fixed/Zend/zend.c:1422:14 #5 0x116f324 in php_execute_script /home/symeon/Desktop/php-7.0_fixed/main/main.c:2471:14 #6 0x16869ad in do_cli /home/symeon/Desktop/php-7.0_fixed/sapi/cli/php_cli.c:971:5 #7 0x1684168 in main /home/symeon/Desktop/php-7.0_fixed/sapi/cli/php_cli.c:1342:18 #8 0x7faeb5d00ec4 in __libc_start_main /build/buildd/eglibc-2.19/csu/libc-start.c:287 #9 0x45f665 in _start (/home/symeon/Desktop/php-7.0_fixed/sapi/cli/php+0x45f665) Address 0x7fff12f060d0 is located in stack of thread T0 at offset 2416 in frame #0 0x12137af in zendparse /home/symeon/Desktop/php-7.0_fixed/Zend/zend_language_parser.c:4035 This frame has 10 object(s): [32, 40) 'yylval' [64, 464) 'yyssa' [528, 2128) 'yyvsa' [2256, 2264) 'yyval' [2288, 2416) 'yymsgbuf' <== Memory access at offset 2416 overflows this variable [2448, 2456) 'yymsg' [2480, 2488) 'yymsg_alloc' [2512, 2528) 'zv' [2544, 2560) 'zv2' [2576, 2592) 'zv3' Did you try to build php with AddressSanitizer and you couldn't reproduce it? Previous Comments: ------------------------------------------------------------------------ [2015-10-12 20:08:05] nikic@php.net I can't repro this myself, could you please check whether the patch at https://github.com/php/php-src/pull/1571 fixes the issue? ------------------------------------------------------------------------ [2015-10-11 14:14:24] nikic@php.net Regardless of whether it crashes or not, our yytnamerr implementation is clearly bogus. The !yyerr branch [1] simply returns yystrlen(yystr), which does not account for the additional information we show in the error message. [1]: http://lxr.php.net/xref/PHP_TRUNK/Zend/zend_language_parser.y#1281 ------------------------------------------------------------------------ [2015-10-11 14:04:22] s dot paraschoudis at gmail dot com Alright, looks like it doesn't crash anymore latest php (rc4) with a non-asan build, but trying with an asan one you should catch it. ------------------------------------------------------------------------ [2015-10-11 13:54:08] s dot paraschoudis at gmail dot com Hi, just tested on RC4 release, it still crashes it.. I have more test cases that trigger it but you should be able to reproduce it.. ------------------------------------------------------------------------ [2015-10-11 13:43:32] felipe@php.net I can't reproduce it. Can you try again? ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=70430 -- Edit this bug report at https://bugs.php.net/bug.php?id=70430&edit=1

« previous php.bugs (#196570) next »