Edit report at https://bugs.php.net/bug.php?id=71683&edit=1
ID: 71683
Updated by: stas@php.net
Reported by: dmoorefo at gmail dot com
Summary: Null pointer dereference in
zend_hash_str_find_bucket
Status: Analyzed
-Type: Security
+Type: Bug
Package: Reproducible crash
Operating System: Ubuntu 14.04.1 32-bit
PHP Version: 7.0.3
Assigned To: yohgaki
Block user comment: N
Private report: Y
New Comment:
Does not look like security issue. It's CLI and requires special settings which are extremely
uncommon for CLI.
Previous Comments:
------------------------------------------------------------------------
[2016-03-09 20:09:04] dmoorefo at gmail dot com
Agreed - the exploitability of this is extremely low and it should be reclassified as a reliability
issue.
I have verified that the patch fixes the issue in 7.0.3 and 7.0.4.
------------------------------------------------------------------------
[2016-03-09 10:14:00] yohgaki@php.net
This is patch fixes the crash.
diff --git a/ext/session/session.c b/ext/session/session.c
index 994d762..d0ee626 100644
--- a/ext/session/session.c
+++ b/ext/session/session.c
@@ -1611,6 +1611,7 @@ PHPAPI void php_session_start(void) /* {{{ */
* '<session-name>=<session-id>' to allow URLs of the form
* http://yoursite/<session-name>=<session-id>/script.php
*/
if (PS(define_sid) && !PS(id) &&
+ zend_is_auto_global_str("_SERVER", sizeof("_SERVER")-1) == SUCCESS
&&
(data = zend_hash_str_find(Z_ARRVAL(PG(http_globals)[TRACK_VARS_SERVER]),
"REQUEST_URI", sizeof("REQUEST_URI") - 1)) &&
Z_TYPE_P(data) == IS_STRING &&
(p = strstr(Z_STRVAL_P(data), PS(session_name))) &&
As I commented earlier, it was jit global issue.
We may fix this as a reliability issue which is a part of security property, but I don't think
this crash is exploitable, is this?
------------------------------------------------------------------------
[2016-03-01 19:07:52] yohgaki@php.net
Offending line should be
(data = zend_hash_str_find(Z_ARRVAL(PG(http_globals)[TRACK_VARS_SERVER]), "REQUEST_URI",
sizeof("REQUEST_URI") - 1))
IIRC, $_SERVER is jit global and it is not initialized here. I'll prepare patch soon, but I
need to check code if initializing array is better or not.
------------------------------------------------------------------------
[2016-03-01 18:58:23] yohgaki@php.net
Ack
------------------------------------------------------------------------
[2016-03-01 15:39:43] johannes@php.net
Assigning to yohgaki who works on session things. I don't think this is a security bug - if you
can run PHP from CLI and use a custom ini you have full power already.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=71683
--
Edit this bug report at https://bugs.php.net/bug.php?id=71683&edit=1