Sec Bug->Bug #70914 [Csd]: zend_throw_or_error() format string vulnerability
| From: | stas@php.net | Date: | Mon, 07 Dec 2015 21:32:41 +0000 |
| Subject: | Sec Bug->Bug #70914 [Csd]: zend_throw_or_error() format string vulnerability | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-197673@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=70914&edit=1
ID: 70914
Updated by: stas@php.net
Reported by: taoguangchen at icloud dot com
Summary: zend_throw_or_error() format string vulnerability
Status: Closed
-Type: Security
+Type: Bug
Package: *General Issues
Operating System: *
PHP Version: 7.0.0RC7
Assigned To: ab
Block user comment: N
Private report: N
Previous Comments:
------------------------------------------------------------------------
[2015-12-07 20:59:04] fernando at inova2b dot com dot br
Thats amazing!
------------------------------------------------------------------------
[2015-11-20 01:03:09] ab@php.net
Automatic comment on behalf of taoguangchen@icloud.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=327b8bf79c5762101ac99930129e2b3e13157c60
Log: Fixed bug #70914 zend_throw_or_error() format string vulnerability
------------------------------------------------------------------------
[2015-11-14 22:55:51] ab@php.net
Huge thanks for the hint. As it's still an RC, marking this as security makes a little sense.
I've just pushed a patch therefore.
Thanks.
------------------------------------------------------------------------
[2015-11-14 16:05:17] taoguangchen at icloud dot com
Description:
------------
```
static void zend_throw_or_error(int fetch_type, zend_class_entry *exception_ce, const char *format,
...) /* {{{ */
{
va_list va;
char *message = NULL;
va_start(va, format);
zend_vspprintf(&message, 0, format, va);
if (fetch_type & ZEND_FETCH_CLASS_EXCEPTION) {
zend_throw_error(exception_ce, message);
} else {
zend_error(E_ERROR, message);
}
efree(message);
va_end(va);
}
```
PoC:
```
$db = new PDO('sqlite::memory:');
$st = $db->query('SELECT 1');
$re = $st->fetchObject('%Z');
```
fix:
```
zend_error(E_ERROR, "%s", message);
```
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=70914&edit=1