Bug #72195 [Opn->Csd]: pg_pconnect/pg_connect cause use-after-free
| From: | laruence@php.net | Date: | Thu, 12 May 2016 05:16:56 +0000 |
| Subject: | Bug #72195 [Opn->Csd]: pg_pconnect/pg_connect cause use-after-free | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-201026@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=72195&edit=1
ID: 72195
Updated by: laruence@php.net
Reported by: fernando at null-life dot com
Summary: pg_pconnect/pg_connect cause use-after-free
-Status: Open
+Status: Closed
Type: Bug
Package: *General Issues
Operating System: Linux
PHP Version: 7.0.6
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of laruence@gmail.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=3c0341e6f9c802ff50cc4eb08e6b90793d033aad
Log: Fixed bug #72195 (pg_pconnect/pg_connect cause use-after-free)
Previous Comments:
------------------------------------------------------------------------
[2016-05-11 12:31:18] fernando at null-life dot com
Description:
------------
This was tested on 32 bits.
pg_pconnect/pg_connect seems to be freeing the value passed as string connection, but when this
value it's an array value, this can still be referenced and causes use-after-free.
In the sample $val is an empty array, but after calling pg_pconnect and other function (tempnam in
this testcases) it will be invalid and overwritten with other values.
From the script output 47464544, this comes from the GFED value in the tempnam call result.
Test script:
---------------
<?php
$val = [];
$var1 = $val;
printf("%x\n", count($val));
@pg_pconnect($var1, "2", "3", "4");
$var1 = "";
tempnam('/tmp', 'ABCDEFGHI');
printf("%x\n", count($val));
Expected result:
----------------
0
0
Actual result:
--------------
0
47464544
php: /home/user/php-7.0/Zend/zend_gc.c:226: gc_possible_root: Assertion `(ref)->gc.u.v.type == 7
|| (ref)->gc.u.v.type == 8' failed.
Aborted
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=72195&edit=1