Bug #70430 [Asn->Csd]: Stack buffer overflow in zend_language_parser()

From: Date: Thu, 15 Oct 2015 20:16:44 +0000
Subject: Bug #70430 [Asn->Csd]: Stack buffer overflow in zend_language_parser()
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-196628@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70430&edit=1 ID: 70430 Updated by: nikic@php.net Reported by: s dot paraschoudis at gmail dot com Summary: Stack buffer overflow in zend_language_parser() -Status: Assigned +Status: Closed Type: Bug Package: Reproducible crash Operating System: Ubuntu 14.04 x32 PHP Version: 7.0.0RC2 Assigned To: nikic Block user comment: N Private report: N New Comment: Automatic comment on behalf of nikic Revision: http://git.php.net/?p=php-src.git;a=commit;h=e3e92e96c158c4fc294ead36f9d73941bdbf679e Log: Fixed bug #70430 Previous Comments: ------------------------------------------------------------------------ [2015-10-15 20:00:11] s dot paraschoudis at gmail dot com Hi, my bad I modified the zend_language_parser.c , sorry! Yeah it fixes this and my other cases. Great! Cheers ------------------------------------------------------------------------ [2015-10-15 19:41:29] nikic@php.net Just did an asan build. I can repro the issue before the patch, but not after the patch. (x64) ------------------------------------------------------------------------ [2015-10-12 21:29:25] s dot paraschoudis at gmail dot com By the way I don't know why the status has changed, sorry for that! ------------------------------------------------------------------------ [2015-10-12 21:24:41] s dot paraschoudis at gmail dot com Hi, it looks like it's still there but this time on line zend_language_parser.c:3268 while ((*yyp = *yyformat) != '\0') <-- according to asan here is where the overflow occurs. Output: ==37540==ERROR: AddressSanitizer: stack-buffer-overflow on address 0x7fff12f060d0 at pc 0x000001227dbd bp 0x7fff12f05490 sp 0x7fff12f05488 WRITE of size 1 at 0x7fff12f060d0 thread T0 #0 0x1227dbc in yysyntax_error /home/symeon/Desktop/php-7.0_fixed/Zend/zend_language_parser.c:3268:18 #1 0x122636a in zendparse /home/symeon/Desktop/php-7.0_fixed/Zend/zend_language_parser.c:6845:33 #2 0x122ed0c in compile_file /home/symeon/Desktop/php-7.0_fixed/Zend/zend_language_scanner.l:591:8 #3 0xd46a25 in phar_compile_file /home/symeon/Desktop/php-7.0_fixed/ext/phar/phar.c:3311:9 #4 0x13650ea in zend_execute_scripts /home/symeon/Desktop/php-7.0_fixed/Zend/zend.c:1422:14 #5 0x116f324 in php_execute_script /home/symeon/Desktop/php-7.0_fixed/main/main.c:2471:14 #6 0x16869ad in do_cli /home/symeon/Desktop/php-7.0_fixed/sapi/cli/php_cli.c:971:5 #7 0x1684168 in main /home/symeon/Desktop/php-7.0_fixed/sapi/cli/php_cli.c:1342:18 #8 0x7faeb5d00ec4 in __libc_start_main /build/buildd/eglibc-2.19/csu/libc-start.c:287 #9 0x45f665 in _start (/home/symeon/Desktop/php-7.0_fixed/sapi/cli/php+0x45f665) Address 0x7fff12f060d0 is located in stack of thread T0 at offset 2416 in frame #0 0x12137af in zendparse /home/symeon/Desktop/php-7.0_fixed/Zend/zend_language_parser.c:4035 This frame has 10 object(s): [32, 40) 'yylval' [64, 464) 'yyssa' [528, 2128) 'yyvsa' [2256, 2264) 'yyval' [2288, 2416) 'yymsgbuf' <== Memory access at offset 2416 overflows this variable [2448, 2456) 'yymsg' [2480, 2488) 'yymsg_alloc' [2512, 2528) 'zv' [2544, 2560) 'zv2' [2576, 2592) 'zv3' Did you try to build php with AddressSanitizer and you couldn't reproduce it? ------------------------------------------------------------------------ [2015-10-12 20:08:05] nikic@php.net I can't repro this myself, could you please check whether the patch at https://github.com/php/php-src/pull/1571 fixes the issue? ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=70430 -- Edit this bug report at https://bugs.php.net/bug.php?id=70430&edit=1

« previous php.bugs (#196628) next »