Bug #71220 [Csd]: Null pointer deref (segfault) in compact via ob_start

From: Date: Sun, 27 Dec 2015 23:18:57 +0000
Subject: Bug #71220 [Csd]: Null pointer deref (segfault) in compact via ob_start
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-198253@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71220&edit=1 ID: 71220 Updated by: stas@php.net Reported by: hugh at allthethings dot co dot nz Summary: Null pointer deref (segfault) in compact via ob_start Status: Closed Type: Bug Package: Reproducible crash Operating System: Linux PHP Version: 7.0.1 Assigned To: laruence Block user comment: N Private report: N New Comment: Hugh, what you mean by "zend defined functions"? compact() is a regular PHP function: http://php.net/manual/en/function.compact.php Previous Comments: ------------------------------------------------------------------------ [2015-12-26 09:01:55] hugh at allthethings dot co dot nz Just to make sure you understand. This requires a different patch to the one you did in bug #71221. I'm a bit confused why the stance from php devs have changed since the comment from an in bug #70183? In my opinion, the big issue here is that you are allowed to call zend defined functions via ob_start instead of just userland defined functions. So far I've filed three independent reports about this and got two patches in and awaiting a third here. I'm positive if I start fuzzing this again I'll find more. If you would like I'm happy collaborating with php to get a patch in that will fix that root issue if I can get guarantee that a patch of that nature would be accepted by upstream. Cheers, Hugh ------------------------------------------------------------------------ [2015-12-26 08:47:46] laruence@php.net simple null pointer deref,and it require specific codes. I don't this this is a security issue. and your patch has been committed, thus closed. thanks ------------------------------------------------------------------------ [2015-12-26 05:47:32] hugh at allthethings dot co dot nz Hi, This is a null pointer deference, which is described on the common weakness enumeration (CWE) list as CWE-476 [1]. It can cause a denial of service, by causing the PHP process to crash unexpectedly (segmentation fault on linux systems). It is similar to bug #70290 which you fixed promptly, and to earlier bugs I filed such as bug #70183 where ab said that similar bugs (null pointer derefence causing crashes) would count as security after PHP 7 was released, which it has. If you would like me to label null pointer derefences as non security issues in future, let me know. Cheers, Hugh [1] - https://cwe.mitre.org/data/definitions/476.html ------------------------------------------------------------------------ [2015-12-26 05:21:44] laruence@php.net I think this is not a security issue, public it. ------------------------------------------------------------------------ [2015-12-26 05:12:57] laruence@php.net I don't understand why this is a security problem? ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=71220 -- Edit this bug report at https://bugs.php.net/bug.php?id=71220&edit=1

« previous php.bugs (#198253) next »