Bug #71220 [Csd]: Null pointer deref (segfault) in compact via ob_start
| From: | hugh at allthethings dot co dot nz | Date: | Mon, 11 Jan 2016 00:01:46 +0000 |
| Subject: | Bug #71220 [Csd]: Null pointer deref (segfault) in compact via ob_start | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-198559@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=71220&edit=1
ID: 71220
User updated by: hugh at allthethings dot co dot nz
Reported by: hugh at allthethings dot co dot nz
Summary: Null pointer deref (segfault) in compact via
ob_start
Status: Closed
Type: Bug
Package: Reproducible crash
Operating System: Linux
PHP Version: 7.0.1
Assigned To: laruence
Block user comment: N
Private report: N
New Comment:
Hi,
Just looking at the patch for this [1], I notice that the test case has the extract function, not
the compact function. Just tested, the extract function doesn't have this issue, so as it is
the test isn't useful.
stas, did my comment above help you understand what I'm seeing as the root cause of this bug?
Cheers,
Hugh
[1] http://git.php.net/?p=php-src.git;a=commitdiff;h=c56efb848b01fa3ecdb7f7253b541b020d154290;hp=6700be67f58611d08bbacc44f327ce98ed0473c9
Previous Comments:
------------------------------------------------------------------------
[2015-12-27 23:26:04] hugh at allthethings dot co dot nz
Hi stas,
I mean functions that are defined in the Zend c language space rather than php userland which I
assume is what ob_start is intended for. Here the compact is. Actually calling zif_compact and in
the other vug reports they are also zif_ functions. Sorry about confusion about what I meant with
Zend defined. Hopefully this clears it uo
------------------------------------------------------------------------
[2015-12-27 23:18:57] stas@php.net
Hugh, what you mean by "zend defined functions"? compact() is a regular PHP function: http://php.net/manual/en/function.compact.php
------------------------------------------------------------------------
[2015-12-26 09:01:55] hugh at allthethings dot co dot nz
Just to make sure you understand. This requires a different patch to the one you did in bug #71221.
I'm a bit confused why the stance from php devs have changed since the comment from an in bug
#70183?
In my opinion, the big issue here is that you are allowed to call zend defined functions via
ob_start instead of just userland defined functions. So far I've filed three independent
reports about this and got two patches in and awaiting a third here. I'm positive if I start
fuzzing this again I'll find more. If you would like I'm happy collaborating with php to
get a patch in that will fix that root issue if I can get guarantee that a patch of that nature
would be accepted by upstream.
Cheers,
Hugh
------------------------------------------------------------------------
[2015-12-26 08:47:46] laruence@php.net
simple null pointer deref,and it require specific codes. I don't this this is a security issue.
and your patch has been committed, thus closed.
thanks
------------------------------------------------------------------------
[2015-12-26 05:47:32] hugh at allthethings dot co dot nz
Hi,
This is a null pointer deference, which is described on the common weakness enumeration (CWE) list
as CWE-476 [1]. It can cause a denial of service, by causing the PHP process to crash unexpectedly
(segmentation fault on linux systems).
It is similar to bug #70290 which you fixed promptly, and to earlier bugs I filed such as bug #70183
where ab said that similar bugs (null pointer derefence causing crashes) would count as security
after PHP 7 was released, which it has.
If you would like me to label null pointer derefences as non security issues in future, let me know.
Cheers,
Hugh
[1] - https://cwe.mitre.org/data/definitions/476.html
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=71220
--
Edit this bug report at https://bugs.php.net/bug.php?id=71220&edit=1