Bug #71220 [Csd]: Null pointer deref (segfault) in compact via ob_start
| From: | stas@php.net | Date: | Sun, 27 Dec 2015 23:18:57 +0000 |
| Subject: | Bug #71220 [Csd]: Null pointer deref (segfault) in compact via ob_start | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-198253@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=71220&edit=1
ID: 71220
Updated by: stas@php.net
Reported by: hugh at allthethings dot co dot nz
Summary: Null pointer deref (segfault) in compact via
ob_start
Status: Closed
Type: Bug
Package: Reproducible crash
Operating System: Linux
PHP Version: 7.0.1
Assigned To: laruence
Block user comment: N
Private report: N
New Comment:
Hugh, what you mean by "zend defined functions"? compact() is a regular PHP function: http://php.net/manual/en/function.compact.php
Previous Comments:
------------------------------------------------------------------------
[2015-12-26 09:01:55] hugh at allthethings dot co dot nz
Just to make sure you understand. This requires a different patch to the one you did in bug #71221.
I'm a bit confused why the stance from php devs have changed since the comment from an in bug
#70183?
In my opinion, the big issue here is that you are allowed to call zend defined functions via
ob_start instead of just userland defined functions. So far I've filed three independent
reports about this and got two patches in and awaiting a third here. I'm positive if I start
fuzzing this again I'll find more. If you would like I'm happy collaborating with php to
get a patch in that will fix that root issue if I can get guarantee that a patch of that nature
would be accepted by upstream.
Cheers,
Hugh
------------------------------------------------------------------------
[2015-12-26 08:47:46] laruence@php.net
simple null pointer deref,and it require specific codes. I don't this this is a security issue.
and your patch has been committed, thus closed.
thanks
------------------------------------------------------------------------
[2015-12-26 05:47:32] hugh at allthethings dot co dot nz
Hi,
This is a null pointer deference, which is described on the common weakness enumeration (CWE) list
as CWE-476 [1]. It can cause a denial of service, by causing the PHP process to crash unexpectedly
(segmentation fault on linux systems).
It is similar to bug #70290 which you fixed promptly, and to earlier bugs I filed such as bug #70183
where ab said that similar bugs (null pointer derefence causing crashes) would count as security
after PHP 7 was released, which it has.
If you would like me to label null pointer derefences as non security issues in future, let me know.
Cheers,
Hugh
[1] - https://cwe.mitre.org/data/definitions/476.html
------------------------------------------------------------------------
[2015-12-26 05:21:44] laruence@php.net
I think this is not a security issue, public it.
------------------------------------------------------------------------
[2015-12-26 05:12:57] laruence@php.net
I don't understand why this is a security problem?
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=71220
--
Edit this bug report at https://bugs.php.net/bug.php?id=71220&edit=1