Bug #72660 [NEW]: NULL Pointer dereference in zend_virtual_cwd

From: Date: Sat, 23 Jul 2016 18:27:14 +0000
Subject: Bug #72660 [NEW]: NULL Pointer dereference in zend_virtual_cwd
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-202538@lists.php.net to get a copy of this message
From: martino dot sani at gmail dot com Operating system: Debian 4.2.3-2 x86_64 PHP version: master-Git-2016-07-23 (Git) Package: *General Issues Bug Type: Bug Bug description:NULL Pointer dereference in zend_virtual_cwd Description: ------------ One of the IS_ABSOLUTE_PATH macro in zend_virtual_cwd.h file does not verify that the path is not null. This could lead to a null pointer dereference issue. I triggered the issue through ZipArchive::addPattern function and ZTS (Zend Thread Safety) enabled, but maybe it could be triggered via different vectors. http://php.net/manual/en/ziparchive.addpattern.php reports that the default value of $path argument is "." but in my test it was null. --- zend_virtual_cwd.h (line 112) --- #ifndef IS_ABSOLUTE_PATH #define IS_ABSOLUTE_PATH(path, len) \ (IS_SLASH(path[0])) #endif --- --- php_zip.c (line 609) --- #ifdef ZTS if (!IS_ABSOLUTE_PATH(path, path_len)) { result = VCWD_GETCWD(cwd, MAXPATHLEN); --- Test script: --------------- --- PHP test script --- $zip = new ZipArchive(); $zip->open("foo.zip", ZIPARCHIVE::CREATE); $zip->addPattern("/\./"); --- --- PHP build --- $ ./configure --enable-zip --enable-maintainer-zts --- Actual result: -------------- Program received signal SIGSEGV, Segmentation fault. 0x0000000001f7e049 in php_zip_pcre (regexp=<optimized out>, path=0x0, path_len=<optimized out>, return_value=<optimized out>) at ext/zip/php_zip.c:610 warning: Source file is more recent than executable. 610 if (!IS_ABSOLUTE_PATH(path, path_len)) { (gdb) bt #0 0x0000000001f7e049 in php_zip_pcre (regexp=<optimized out>, path=0x0, path_len=<optimized out>, return_value=<optimized out>) at ext/zip/php_zip.c:610 #1 0x0000000001f9cb8b in php_zip_add_from_pattern (execute_data=<optimized out>, return_value=<optimized out>, type=<optimized out>) at ext/zip/php_zip.c:1669 #2 0x000000000276ddd4 in ZEND_DO_FCALL_SPEC_RETVAL_UNUSED_HANDLER (execute_data=<optimized out>) at Zend/zend_vm_execute.h:970 #3 0x0000000002673052 in execute_ex (ex=<optimized out>) at Zend/zend_vm_execute.h:432 #4 0x0000000002673c2f in zend_execute (op_array=<optimized out>, return_value=<optimized out>) at Zend/zend_vm_execute.h:474 #5 0x000000000242b711 in zend_execute_scripts (type=<optimized out>, retval=<optimized out>, file_count=<optimized out>) at Zend/zend.c:1447 #6 0x000000000202ccce in php_execute_script (primary_file=0x7fffffffcd20) at main/main.c:2533 #7 0x0000000002a97fe3 in do_cli (argc=<optimized out>, argv=<optimized out>) at sapi/cli/php_cli.c:990 #8 0x0000000002a9385c in main (argc=3, argv=0x60300000ee30) at sapi/cli/php_cli.c:1378 (gdb) info args regexp = <optimized out> path = 0x0 -- Edit bug report at https://bugs.php.net/bug.php?id=72660&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=72660&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=72660&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=72660&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=72660&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=72660&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=72660&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=72660&r=needscript Try newer version: https://bugs.php.net/fix.php?id=72660&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=72660&r=support Expected behavior: https://bugs.php.net/fix.php?id=72660&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=72660&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=72660&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=72660&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=72660&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=72660&r=dst IIS Stability: https://bugs.php.net/fix.php?id=72660&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=72660&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=72660&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=72660&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=72660&r=mysqlcfg

« previous php.bugs (#202538) next »