Sec Bug->Bug #72142 [Opn]: WDDX Packet Injection Vulnerability in wddx_serialize_value()
| From: | stas@php.net | Date: | Tue, 10 May 2016 05:30:19 +0000 |
| Subject: | Sec Bug->Bug #72142 [Opn]: WDDX Packet Injection Vulnerability in wddx_serialize_value() | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-200981@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=72142&edit=1
ID: 72142
Updated by: stas@php.net
Reported by: taoguangchen at icloud dot com
Summary: WDDX Packet Injection Vulnerability in
wddx_serialize_value()
Status: Open
-Type: Security
+Type: Bug
Package: WDDX related
Operating System: *
PHP Version: 5.5.35
Block user comment: N
Private report: Y
New Comment:
Doesn't look like security issue - you can just compose any string you like and call it
"wddx serialized", so I don't see any vulnerability here.
Previous Comments:
------------------------------------------------------------------------
[2016-05-03 12:14:47] taoguangchen at icloud dot com
Description:
------------
```
void php_wddx_packet_start(wddx_packet *packet, char *comment, int comment_len)
{
php_wddx_add_chunk_static(packet, WDDX_PACKET_S);
if (comment) {
php_wddx_add_chunk_static(packet, WDDX_HEADER_S);
php_wddx_add_chunk_static(packet, WDDX_COMMENT_S);
php_wddx_add_chunk_ex(packet, comment, comment_len);
php_wddx_add_chunk_static(packet, WDDX_COMMENT_E);
php_wddx_add_chunk_static(packet, WDDX_HEADER_E);
...
PHP_FUNCTION(wddx_serialize_value)
{
...
if (zend_parse_parameters(ZEND_NUM_ARGS() TSRMLS_CC, "z|s", &var, &comment,
&comment_len) == FAILURE) {
return;
}
...
php_wddx_packet_start(packet, comment, comment_len);
```
The wddx_serialize_value()'s second parameter
comment is not filtered, that
results in arbitrarily wddx packet injection vulnerability.
PoC:
```
<?php
$wddx = wddx_serialize_value('',
'</comment></header><data><struct><var
name="php_class_name"><string>stdClass</string></var></struct></data></wddxPacket>');
var_dump(wddx_deserialize($wddx));
?>
```
Fix:
```
void php_wddx_packet_start(wddx_packet *packet, char *comment, int comment_len)
{
php_wddx_add_chunk_static(packet, WDDX_PACKET_S);
if (comment) {
+ size_t comment_esc_len;
+ char *comment_esc;
+ comment_esc = php_escape_html_entities(comment, comment_len, &comment_esc_len, 0, ENT_QUOTES,
NULL TSRMLS_CC);
php_wddx_add_chunk_static(packet, WDDX_HEADER_S);
php_wddx_add_chunk_static(packet, WDDX_COMMENT_S);
- php_wddx_add_chunk_ex(packet, comment, comment_len);
+ php_wddx_add_chunk_ex(packet, comment_esc, comment_esc_len);
php_wddx_add_chunk_static(packet, WDDX_COMMENT_E);
php_wddx_add_chunk_static(packet, WDDX_HEADER_E);
efree(comment_esc);
} else {
```
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=72142&edit=1