Bug #72531 [Opn->Csd]: ps_files_cleanup_dir Buffer overflow
| From: | laruence@php.net | Date: | Sun, 03 Jul 2016 01:31:26 +0000 |
| Subject: | Bug #72531 [Opn->Csd]: ps_files_cleanup_dir Buffer overflow | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-201996@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=72531&edit=1
ID: 72531
Updated by: laruence@php.net
Reported by: dotagosudaily at gmail dot com
Summary: ps_files_cleanup_dir Buffer overflow
-Status: Open
+Status: Closed
Type: Bug
Package: Session related
Operating System: All
PHP Version: 7.1.0alpha1
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of laruence@gmail.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=6744737577bcbae4ff3d0082f23c9282758cacbb
Log: Fixed bug #72531 (ps_files_cleanup_dir Buffer overflow)
Previous Comments:
------------------------------------------------------------------------
[2016-07-02 08:21:06] stas@php.net
Not a security issue - session.save_path is not a setting that should be accessible to remote user,
it's an automatic arbitrary file write.
------------------------------------------------------------------------
[2016-07-02 01:36:53] dotagosudaily at gmail dot com
Description:
------------
ext/session/mod_files.c:276
static int ps_files_cleanup_dir(const char *dirname, zend_long maxlifetime)
{
...
char buf[MAXPATHLEN];
...
dirname_len = strlen(dirname);
memcpy(buf, dirname, dirname_len);
...
buf is static buffer declared with size MAXPATHLEN ( 256 bytes )
length of dirname never check with MAXPATHLEN
when dirname len > 256 it will overflow
When run php under debugger we observered:
Breakpoint 2, ps_files_cleanup_dir (dirname=0xf7a72000 'A' <repeats 200 times>...,
maxlifetime=0x5a0) at /home/suto/php-src-master/ext/session/mod_files.c:298
298 memcpy(buf, dirname, dirname_len);
gdb$ p dirname_len
$1 = 0xfb0
0xfb0 is len of directory we created and larger more than 256.
Test script:
---------------
$fname =
"AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/";
$dirname = str_repeat($fname,16);
//wp_mkdir_p($dirname); Make a directory with name $fname
ini_set('session.save_path',$dirname);
ini_set('session.gc_probability', 1000);
session_start();
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=72531&edit=1