Bug #70430 [Com]: Stack buffer overflow in zend_language_parser()
| From: | s dot paraschoudis at gmail dot com | Date: | Mon, 12 Oct 2015 21:29:25 +0000 |
| Subject: | Bug #70430 [Com]: Stack buffer overflow in zend_language_parser() | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-196571@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=70430&edit=1
ID: 70430
Comment by: s dot paraschoudis at gmail dot com
Reported by: s dot paraschoudis at gmail dot com
Summary: Stack buffer overflow in zend_language_parser()
Status: Assigned
Type: Bug
Package: Reproducible crash
Operating System: Ubuntu 14.04 x32
PHP Version: 7.0.0RC2
Assigned To: nikic
Block user comment: N
Private report: N
New Comment:
By the way I don't know why the status has changed, sorry for that!
Previous Comments:
------------------------------------------------------------------------
[2015-10-12 21:24:41] s dot paraschoudis at gmail dot com
Hi, it looks like it's still there but this time on line zend_language_parser.c:3268
while ((*yyp = *yyformat) != '\0') <-- according to asan here is where the overflow
occurs.
Output:
==37540==ERROR: AddressSanitizer: stack-buffer-overflow on address 0x7fff12f060d0 at pc
0x000001227dbd bp 0x7fff12f05490 sp 0x7fff12f05488
WRITE of size 1 at 0x7fff12f060d0 thread T0
#0 0x1227dbc in yysyntax_error
/home/symeon/Desktop/php-7.0_fixed/Zend/zend_language_parser.c:3268:18
#1 0x122636a in zendparse /home/symeon/Desktop/php-7.0_fixed/Zend/zend_language_parser.c:6845:33
#2 0x122ed0c in compile_file
/home/symeon/Desktop/php-7.0_fixed/Zend/zend_language_scanner.l:591:8
#3 0xd46a25 in phar_compile_file /home/symeon/Desktop/php-7.0_fixed/ext/phar/phar.c:3311:9
#4 0x13650ea in zend_execute_scripts /home/symeon/Desktop/php-7.0_fixed/Zend/zend.c:1422:14
#5 0x116f324 in php_execute_script /home/symeon/Desktop/php-7.0_fixed/main/main.c:2471:14
#6 0x16869ad in do_cli /home/symeon/Desktop/php-7.0_fixed/sapi/cli/php_cli.c:971:5
#7 0x1684168 in main /home/symeon/Desktop/php-7.0_fixed/sapi/cli/php_cli.c:1342:18
#8 0x7faeb5d00ec4 in __libc_start_main /build/buildd/eglibc-2.19/csu/libc-start.c:287
#9 0x45f665 in _start (/home/symeon/Desktop/php-7.0_fixed/sapi/cli/php+0x45f665)
Address 0x7fff12f060d0 is located in stack of thread T0 at offset 2416 in frame
#0 0x12137af in zendparse /home/symeon/Desktop/php-7.0_fixed/Zend/zend_language_parser.c:4035
This frame has 10 object(s):
[32, 40) 'yylval'
[64, 464) 'yyssa'
[528, 2128) 'yyvsa'
[2256, 2264) 'yyval'
[2288, 2416) 'yymsgbuf' <== Memory access at offset 2416 overflows this variable
[2448, 2456) 'yymsg'
[2480, 2488) 'yymsg_alloc'
[2512, 2528) 'zv'
[2544, 2560) 'zv2'
[2576, 2592) 'zv3'
Did you try to build php with AddressSanitizer and you couldn't reproduce it?
------------------------------------------------------------------------
[2015-10-12 20:08:05] nikic@php.net
I can't repro this myself, could you please check whether the patch at https://github.com/php/php-src/pull/1571 fixes
the issue?
------------------------------------------------------------------------
[2015-10-11 14:14:24] nikic@php.net
Regardless of whether it crashes or not, our yytnamerr implementation is clearly bogus. The !yyerr
branch [1] simply returns yystrlen(yystr), which does not account for the additional information we
show in the error message.
[1]: http://lxr.php.net/xref/PHP_TRUNK/Zend/zend_language_parser.y#1281
------------------------------------------------------------------------
[2015-10-11 14:04:22] s dot paraschoudis at gmail dot com
Alright, looks like it doesn't crash anymore latest php (rc4) with a non-asan build,
but trying with an asan one you should catch it.
------------------------------------------------------------------------
[2015-10-11 13:54:08] s dot paraschoudis at gmail dot com
Hi, just tested on RC4 release, it still crashes it..
I have more test cases that trigger it but you should be able to reproduce it..
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=70430
--
Edit this bug report at https://bugs.php.net/bug.php?id=70430&edit=1