Sec Bug->Bug #72142 [Opn]: WDDX Packet Injection Vulnerability in wddx_serialize_value()

From: Date: Tue, 10 May 2016 05:30:19 +0000
Subject: Sec Bug->Bug #72142 [Opn]: WDDX Packet Injection Vulnerability in wddx_serialize_value()
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-200981@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72142&edit=1 ID: 72142 Updated by: stas@php.net Reported by: taoguangchen at icloud dot com Summary: WDDX Packet Injection Vulnerability in wddx_serialize_value() Status: Open -Type: Security +Type: Bug Package: WDDX related Operating System: * PHP Version: 5.5.35 Block user comment: N Private report: Y New Comment: Doesn't look like security issue - you can just compose any string you like and call it "wddx serialized", so I don't see any vulnerability here. Previous Comments: ------------------------------------------------------------------------ [2016-05-03 12:14:47] taoguangchen at icloud dot com Description: ------------ ``` void php_wddx_packet_start(wddx_packet *packet, char *comment, int comment_len) { php_wddx_add_chunk_static(packet, WDDX_PACKET_S); if (comment) { php_wddx_add_chunk_static(packet, WDDX_HEADER_S); php_wddx_add_chunk_static(packet, WDDX_COMMENT_S); php_wddx_add_chunk_ex(packet, comment, comment_len); php_wddx_add_chunk_static(packet, WDDX_COMMENT_E); php_wddx_add_chunk_static(packet, WDDX_HEADER_E); ... PHP_FUNCTION(wddx_serialize_value) { ... if (zend_parse_parameters(ZEND_NUM_ARGS() TSRMLS_CC, "z|s", &var, &comment, &comment_len) == FAILURE) { return; } ... php_wddx_packet_start(packet, comment, comment_len); ``` The wddx_serialize_value()'s second parameter comment is not filtered, that results in arbitrarily wddx packet injection vulnerability. PoC: ``` <?php $wddx = wddx_serialize_value('', '</comment></header><data><struct><var name="php_class_name"><string>stdClass</string></var></struct></data></wddxPacket>'); var_dump(wddx_deserialize($wddx)); ?> ``` Fix: ``` void php_wddx_packet_start(wddx_packet *packet, char *comment, int comment_len) { php_wddx_add_chunk_static(packet, WDDX_PACKET_S); if (comment) { + size_t comment_esc_len; + char *comment_esc; + comment_esc = php_escape_html_entities(comment, comment_len, &comment_esc_len, 0, ENT_QUOTES, NULL TSRMLS_CC); php_wddx_add_chunk_static(packet, WDDX_HEADER_S); php_wddx_add_chunk_static(packet, WDDX_COMMENT_S); - php_wddx_add_chunk_ex(packet, comment, comment_len); + php_wddx_add_chunk_ex(packet, comment_esc, comment_esc_len); php_wddx_add_chunk_static(packet, WDDX_COMMENT_E); php_wddx_add_chunk_static(packet, WDDX_HEADER_E); efree(comment_esc); } else { ``` ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=72142&edit=1

« previous php.bugs (#200981) next »