Sec Bug->Bug #72195 [Opn]: pg_pconnect/pg_connect cause use-after-free

From: Date: Wed, 11 May 2016 16:16:46 +0000
Subject: Sec Bug->Bug #72195 [Opn]: pg_pconnect/pg_connect cause use-after-free
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-201023@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72195&edit=1 ID: 72195 Updated by: stas@php.net Reported by: fernando at null-life dot com Summary: pg_pconnect/pg_connect cause use-after-free Status: Open -Type: Security +Type: Bug Package: *General Issues Operating System: Linux PHP Version: 7.0.6 Block user comment: N Private report: Y Previous Comments: ------------------------------------------------------------------------ [2016-05-11 12:31:18] fernando at null-life dot com Description: ------------ This was tested on 32 bits. pg_pconnect/pg_connect seems to be freeing the value passed as string connection, but when this value it's an array value, this can still be referenced and causes use-after-free. In the sample $val is an empty array, but after calling pg_pconnect and other function (tempnam in this testcases) it will be invalid and overwritten with other values. From the script output 47464544, this comes from the GFED value in the tempnam call result. Test script: --------------- <?php $val = []; $var1 = $val; printf("%x\n", count($val)); @pg_pconnect($var1, "2", "3", "4"); $var1 = ""; tempnam('/tmp', 'ABCDEFGHI'); printf("%x\n", count($val)); Expected result: ---------------- 0 0 Actual result: -------------- 0 47464544 php: /home/user/php-7.0/Zend/zend_gc.c:226: gc_possible_root: Assertion `(ref)->gc.u.v.type == 7 || (ref)->gc.u.v.type == 8' failed. Aborted ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=72195&edit=1

« previous php.bugs (#201023) next »