Bug #72142 [Opn->Csd]: WDDX Packet Injection Vulnerability in wddx_serialize_value()
| From: | nikic@php.net | Date: | Sat, 30 Jul 2016 13:55:49 +0000 |
| Subject: | Bug #72142 [Opn->Csd]: WDDX Packet Injection Vulnerability in wddx_serialize_value() | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-202727@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=72142&edit=1
ID: 72142
Updated by: nikic@php.net
Reported by: taoguangchen at icloud dot com
Summary: WDDX Packet Injection Vulnerability in
wddx_serialize_value()
-Status: Open
+Status: Closed
Type: Bug
Package: WDDX related
Operating System: *
PHP Version: 5.6.21
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of nikic
Revision: http://git.php.net/?p=php-src.git;a=commit;h=e87ac688d5e700fdb56b37fda8b011d6b05b97fc
Log: Fixed bug #72142
Previous Comments:
------------------------------------------------------------------------
[2016-05-10 05:30:19] stas@php.net
Doesn't look like security issue - you can just compose any string you like and call it
"wddx serialized", so I don't see any vulnerability here.
------------------------------------------------------------------------
[2016-05-03 12:14:47] taoguangchen at icloud dot com
Description:
------------
```
void php_wddx_packet_start(wddx_packet *packet, char *comment, int comment_len)
{
php_wddx_add_chunk_static(packet, WDDX_PACKET_S);
if (comment) {
php_wddx_add_chunk_static(packet, WDDX_HEADER_S);
php_wddx_add_chunk_static(packet, WDDX_COMMENT_S);
php_wddx_add_chunk_ex(packet, comment, comment_len);
php_wddx_add_chunk_static(packet, WDDX_COMMENT_E);
php_wddx_add_chunk_static(packet, WDDX_HEADER_E);
...
PHP_FUNCTION(wddx_serialize_value)
{
...
if (zend_parse_parameters(ZEND_NUM_ARGS() TSRMLS_CC, "z|s", &var, &comment,
&comment_len) == FAILURE) {
return;
}
...
php_wddx_packet_start(packet, comment, comment_len);
```
The wddx_serialize_value()'s second parameter
comment is not filtered, that
results in arbitrarily wddx packet injection vulnerability.
PoC:
```
<?php
$wddx = wddx_serialize_value('',
'</comment></header><data><struct><var
name="php_class_name"><string>stdClass</string></var></struct></data></wddxPacket>');
var_dump(wddx_deserialize($wddx));
?>
```
Fix:
```
void php_wddx_packet_start(wddx_packet *packet, char *comment, int comment_len)
{
php_wddx_add_chunk_static(packet, WDDX_PACKET_S);
if (comment) {
+ size_t comment_esc_len;
+ char *comment_esc;
+ comment_esc = php_escape_html_entities(comment, comment_len, &comment_esc_len, 0, ENT_QUOTES,
NULL TSRMLS_CC);
php_wddx_add_chunk_static(packet, WDDX_HEADER_S);
php_wddx_add_chunk_static(packet, WDDX_COMMENT_S);
- php_wddx_add_chunk_ex(packet, comment, comment_len);
+ php_wddx_add_chunk_ex(packet, comment_esc, comment_esc_len);
php_wddx_add_chunk_static(packet, WDDX_COMMENT_E);
php_wddx_add_chunk_static(packet, WDDX_HEADER_E);
efree(comment_esc);
} else {
```
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=72142&edit=1