Bug #71683 [Ana]: Null pointer dereference in zend_hash_str_find_bucket

From: Date: Fri, 11 Mar 2016 23:19:15 +0000
Subject: Bug #71683 [Ana]: Null pointer dereference in zend_hash_str_find_bucket
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-199768@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71683&edit=1 ID: 71683 Updated by: yohgaki@php.net Reported by: dmoorefo at gmail dot com Summary: Null pointer dereference in zend_hash_str_find_bucket Status: Analyzed Type: Bug Package: Reproducible crash Operating System: Ubuntu 14.04.1 32-bit PHP Version: 7.0.3 Assigned To: yohgaki Block user comment: N Private report: N New Comment: Related to #71754 The fix committed for #71754 breaks transid. Correct patch will be committed soon. Previous Comments: ------------------------------------------------------------------------ [2016-03-11 01:33:59] yohgaki@php.net OK. I'll just merge the fix to branches. ------------------------------------------------------------------------ [2016-03-11 01:33:11] yohgaki@php.net Related To: Bug #71599 ------------------------------------------------------------------------ [2016-03-09 22:42:59] stas@php.net Does not look like security issue. It's CLI and requires special settings which are extremely uncommon for CLI. ------------------------------------------------------------------------ [2016-03-09 20:09:04] dmoorefo at gmail dot com Agreed - the exploitability of this is extremely low and it should be reclassified as a reliability issue. I have verified that the patch fixes the issue in 7.0.3 and 7.0.4. ------------------------------------------------------------------------ [2016-03-09 10:14:00] yohgaki@php.net This is patch fixes the crash. diff --git a/ext/session/session.c b/ext/session/session.c index 994d762..d0ee626 100644 --- a/ext/session/session.c +++ b/ext/session/session.c @@ -1611,6 +1611,7 @@ PHPAPI void php_session_start(void) /* {{{ */ * '<session-name>=<session-id>' to allow URLs of the form * http://yoursite/<session-name>=<session-id>/script.php */ if (PS(define_sid) && !PS(id) && + zend_is_auto_global_str("_SERVER", sizeof("_SERVER")-1) == SUCCESS && (data = zend_hash_str_find(Z_ARRVAL(PG(http_globals)[TRACK_VARS_SERVER]), "REQUEST_URI", sizeof("REQUEST_URI") - 1)) && Z_TYPE_P(data) == IS_STRING && (p = strstr(Z_STRVAL_P(data), PS(session_name))) && As I commented earlier, it was jit global issue. We may fix this as a reliability issue which is a part of security property, but I don't think this crash is exploitable, is this? ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=71683 -- Edit this bug report at https://bugs.php.net/bug.php?id=71683&edit=1

« previous php.bugs (#199768) next »