Bug #72535 [Opn->Ver]: arcfour encryption stream filter crashes php

From: Date: Tue, 05 Jul 2016 11:13:33 +0000
Subject: Bug #72535 [Opn->Ver]: arcfour encryption stream filter crashes php
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-202061@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72535&edit=1

 ID:                 72535
 Updated by:         cmb@php.net
 Reported by:        terrafrost at gmail dot com
 Summary:            arcfour encryption stream filter crashes php
-Status:             Open
+Status:             Verified
 Type:               Bug
 Package:            Reproducible crash
 Operating System:   *
 PHP Version:        7.0.8
 Block user comment: N
 Private report:     N

 New Comment:

I did some debugging, but am not able to resolve the issue. The
following debug hints might be helpful, nonetheless. Note that this
appears to happen only for x86 builds:

 * set two breakpoints:
   <https://github.com/php/php-src/blob/php-7.0.8/main/streams/streams.c#L1180>
   <https://github.com/php/php-src/blob/php-7.0.8/main/streams/memory.c#L68>
 * start debugging
 * when reaching the first breakpoint set watches for the memory
   locations of bucket and stream->abstract, e.g.
   (_php_stream_bucket*)0x00c02b98
   (php_stream_memory_data*)0x00c5cb10
 * continue to the second breakpoint; everything is fine until now
 * step over the assignment
 * now ms->data points to the exact location of bucket
 * a few lines below[1] the buf gets memcpy()d to ms->data,
   thereby overwriting and corrupting bucket, which results in an
   invalid read in php_stream_bucket_unlink() (one statement after
   the first breakpoint)
 
[1] <https://github.com/php/php-src/blob/php-7.0.8/main/streams/memory.c#L76>


Previous Comments:
------------------------------------------------------------------------
[2016-07-04 19:28:28] cmb@php.net

I've got the following backtrace with a recent master (421cc65)
and an x86 build (apparently the crash doesn't happen with x64
builds):

php7ts_debug.dll!php_stream_bucket_unlink(_php_stream_bucket * bucket) Line 225
php7ts_debug.dll!_php_stream_write_filtered(_php_stream * stream, const char * buf, unsigned int
count, int flags) Line 1186
php7ts_debug.dll!_php_stream_write(_php_stream * stream, const char * buf, unsigned int count) Line
1229
php7ts_debug.dll!zif_fwrite(_zend_execute_data * execute_data, _zval_struct * return_value) Line
1214
php7ts_debug.dll!ZEND_DO_ICALL_SPEC_RETVAL_UNUSED_HANDLER(_zend_execute_data * execute_data) Line
632
php7ts_debug.dll!execute_ex(_zend_execute_data * ex) Line 432
php7ts_debug.dll!zend_execute(_zend_op_array * op_array, _zval_struct * return_value) Line 474
php7ts_debug.dll!zend_execute_scripts(int type, _zval_struct * retval, int file_count, ...) Line
1441
php7ts_debug.dll!php_execute_script(_zend_file_handle * primary_file) Line 2532
php.exe!do_cli(int argc, char * * argv) Line 990
php.exe!main(int argc, char * * argv) Line 1378
[External Code]
[Frames below may be incorrect and/or missing, no symbols loaded for kernel32.dll]

------------------------------------------------------------------------
[2016-07-04 02:50:20] kalle@php.net

Thank you for this bug report. To properly diagnose the problem, we
need a backtrace to see what is happening behind the scenes. To
find out how to generate a backtrace, please read
http://bugs.php.net/bugs-generating-backtrace.php
for *NIX and
http://bugs.php.net/bugs-generating-backtrace-win32.php
for Win32

Once you have generated a backtrace, please submit it to this bug
report and change the status back to "Open". Thank you for helping
us make PHP better.



------------------------------------------------------------------------
[2016-07-03 13:07:20] cmb@php.net

I can reproduce the crash with PHP 5.6.23, PHP 7.0.8 and PHP
7.1.0alpha2 on Windows. A debug build of current master on Linux
reports 2 memory leaks.

------------------------------------------------------------------------
[2016-07-03 05:55:29] terrafrost at gmail dot com

Description:
------------
I don't think encryption filters are a very well known feature of mcrypt but none-the-less they
are a feature: http://php.net/manual/en/filters.encryption.php

The example in the PHP docs (with tripledes) works but arcfour does not work - you try to run it and
you get a segfault.

Test script:
---------------
<?php
$passphrase = 'My secret';
$plaintext = 'Secret secret secret data';

$iv = substr(md5('iv' . $passphrase, true), 0, 8);
$key = substr(md5('pass1' . $passphrase, true) .
              md5('pass2' . $passphrase, true), 0, 24);
$opts = array('iv' => $iv, 'key' => $key, 'mode' =>
'stream');

$expected = substr($plaintext . $plaintext, 0, 48);

$fp = fopen('php://memory', 'wb+');
stream_filter_append($fp, 'mcrypt.arcfour', STREAM_FILTER_WRITE, $opts);
fwrite($fp, $plaintext);

Expected result:
----------------
The script to actually run

Actual result:
--------------
The script crashes


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=72535&edit=1


Thread (5 messages)

« previous php.bugs (#202061) next »