Sec Bug->Bug #70914 [Csd]: zend_throw_or_error() format string vulnerability

From: Date: Mon, 07 Dec 2015 21:32:41 +0000
Subject: Sec Bug->Bug #70914 [Csd]: zend_throw_or_error() format string vulnerability
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-197673@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70914&edit=1 ID: 70914 Updated by: stas@php.net Reported by: taoguangchen at icloud dot com Summary: zend_throw_or_error() format string vulnerability Status: Closed -Type: Security +Type: Bug Package: *General Issues Operating System: * PHP Version: 7.0.0RC7 Assigned To: ab Block user comment: N Private report: N Previous Comments: ------------------------------------------------------------------------ [2015-12-07 20:59:04] fernando at inova2b dot com dot br Thats amazing! ------------------------------------------------------------------------ [2015-11-20 01:03:09] ab@php.net Automatic comment on behalf of taoguangchen@icloud.com Revision: http://git.php.net/?p=php-src.git;a=commit;h=327b8bf79c5762101ac99930129e2b3e13157c60 Log: Fixed bug #70914 zend_throw_or_error() format string vulnerability ------------------------------------------------------------------------ [2015-11-14 22:55:51] ab@php.net Huge thanks for the hint. As it's still an RC, marking this as security makes a little sense. I've just pushed a patch therefore. Thanks. ------------------------------------------------------------------------ [2015-11-14 16:05:17] taoguangchen at icloud dot com Description: ------------ ``` static void zend_throw_or_error(int fetch_type, zend_class_entry *exception_ce, const char *format, ...) /* {{{ */ { va_list va; char *message = NULL; va_start(va, format); zend_vspprintf(&message, 0, format, va); if (fetch_type & ZEND_FETCH_CLASS_EXCEPTION) { zend_throw_error(exception_ce, message); } else { zend_error(E_ERROR, message); } efree(message); va_end(va); } ``` PoC: ``` $db = new PDO('sqlite::memory:'); $st = $db->query('SELECT 1'); $re = $st->fetchObject('%Z'); ``` fix: ``` zend_error(E_ERROR, "%s", message); ``` ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=70914&edit=1

« previous php.bugs (#197673) next »