Sec Bug->Bug #71683 [Ana]: Null pointer dereference in zend_hash_str_find_bucket

From: Date: Wed, 09 Mar 2016 22:42:59 +0000
Subject: Sec Bug->Bug #71683 [Ana]: Null pointer dereference in zend_hash_str_find_bucket
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-199716@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71683&edit=1

 ID:                 71683
 Updated by:         stas@php.net
 Reported by:        dmoorefo at gmail dot com
 Summary:            Null pointer dereference in
                     zend_hash_str_find_bucket
 Status:             Analyzed
-Type:               Security
+Type:               Bug
 Package:            Reproducible crash
 Operating System:   Ubuntu 14.04.1 32-bit
 PHP Version:        7.0.3
 Assigned To:        yohgaki
 Block user comment: N
 Private report:     Y

 New Comment:

Does not look like security issue. It's CLI and requires special settings which are extremely
uncommon for CLI.


Previous Comments:
------------------------------------------------------------------------
[2016-03-09 20:09:04] dmoorefo at gmail dot com

Agreed - the exploitability of this is extremely low and it should be reclassified as a reliability
issue.

I have verified that the patch fixes the issue in 7.0.3 and 7.0.4.

------------------------------------------------------------------------
[2016-03-09 10:14:00] yohgaki@php.net

This is patch fixes the crash.

diff --git a/ext/session/session.c b/ext/session/session.c
index 994d762..d0ee626 100644
--- a/ext/session/session.c
+++ b/ext/session/session.c
@@ -1611,6 +1611,7 @@ PHPAPI void php_session_start(void) /* {{{ */
 		 * '<session-name>=<session-id>' to allow URLs of the form
 		 * http://yoursite/<session-name>=<session-id>/script.php
*/
 		if (PS(define_sid) && !PS(id) &&
+			zend_is_auto_global_str("_SERVER", sizeof("_SERVER")-1) == SUCCESS
&&
 			(data = zend_hash_str_find(Z_ARRVAL(PG(http_globals)[TRACK_VARS_SERVER]),
"REQUEST_URI", sizeof("REQUEST_URI") - 1)) &&
 			Z_TYPE_P(data) == IS_STRING &&
 			(p = strstr(Z_STRVAL_P(data), PS(session_name))) &&

As I commented earlier, it was jit global issue.
We may fix this as a reliability issue which is a part of security property, but I don't think
this crash is exploitable, is this?

------------------------------------------------------------------------
[2016-03-01 19:07:52] yohgaki@php.net

Offending line should be 

(data = zend_hash_str_find(Z_ARRVAL(PG(http_globals)[TRACK_VARS_SERVER]), "REQUEST_URI",
sizeof("REQUEST_URI") - 1))

IIRC, $_SERVER is jit global and it is not initialized here. I'll prepare patch soon, but I
need to check code if initializing array is better or not.

------------------------------------------------------------------------
[2016-03-01 18:58:23] yohgaki@php.net

Ack

------------------------------------------------------------------------
[2016-03-01 15:39:43] johannes@php.net

Assigning to yohgaki who works on session things. I don't think this is a security bug - if you
can run PHP from CLI and use a custom ini you have full power already.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=71683


--
Edit this bug report at https://bugs.php.net/bug.php?id=71683&edit=1


Thread (1 message)

  • stas@php.net
  • Unknown Message
    • stas@php.net
« previous php.bugs (#199716) next »