Bug #72142 [Opn->Csd]: WDDX Packet Injection Vulnerability in wddx_serialize_value()

From: Date: Sat, 30 Jul 2016 13:55:49 +0000
Subject: Bug #72142 [Opn->Csd]: WDDX Packet Injection Vulnerability in wddx_serialize_value()
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-202727@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72142&edit=1 ID: 72142 Updated by: nikic@php.net Reported by: taoguangchen at icloud dot com Summary: WDDX Packet Injection Vulnerability in wddx_serialize_value() -Status: Open +Status: Closed Type: Bug Package: WDDX related Operating System: * PHP Version: 5.6.21 Block user comment: N Private report: N New Comment: Automatic comment on behalf of nikic Revision: http://git.php.net/?p=php-src.git;a=commit;h=e87ac688d5e700fdb56b37fda8b011d6b05b97fc Log: Fixed bug #72142 Previous Comments: ------------------------------------------------------------------------ [2016-05-10 05:30:19] stas@php.net Doesn't look like security issue - you can just compose any string you like and call it "wddx serialized", so I don't see any vulnerability here. ------------------------------------------------------------------------ [2016-05-03 12:14:47] taoguangchen at icloud dot com Description: ------------ ``` void php_wddx_packet_start(wddx_packet *packet, char *comment, int comment_len) { php_wddx_add_chunk_static(packet, WDDX_PACKET_S); if (comment) { php_wddx_add_chunk_static(packet, WDDX_HEADER_S); php_wddx_add_chunk_static(packet, WDDX_COMMENT_S); php_wddx_add_chunk_ex(packet, comment, comment_len); php_wddx_add_chunk_static(packet, WDDX_COMMENT_E); php_wddx_add_chunk_static(packet, WDDX_HEADER_E); ... PHP_FUNCTION(wddx_serialize_value) { ... if (zend_parse_parameters(ZEND_NUM_ARGS() TSRMLS_CC, "z|s", &var, &comment, &comment_len) == FAILURE) { return; } ... php_wddx_packet_start(packet, comment, comment_len); ``` The wddx_serialize_value()'s second parameter comment is not filtered, that results in arbitrarily wddx packet injection vulnerability. PoC: ``` <?php $wddx = wddx_serialize_value('', '</comment></header><data><struct><var name="php_class_name"><string>stdClass</string></var></struct></data></wddxPacket>'); var_dump(wddx_deserialize($wddx)); ?> ``` Fix: ``` void php_wddx_packet_start(wddx_packet *packet, char *comment, int comment_len) { php_wddx_add_chunk_static(packet, WDDX_PACKET_S); if (comment) { + size_t comment_esc_len; + char *comment_esc; + comment_esc = php_escape_html_entities(comment, comment_len, &comment_esc_len, 0, ENT_QUOTES, NULL TSRMLS_CC); php_wddx_add_chunk_static(packet, WDDX_HEADER_S); php_wddx_add_chunk_static(packet, WDDX_COMMENT_S); - php_wddx_add_chunk_ex(packet, comment, comment_len); + php_wddx_add_chunk_ex(packet, comment_esc, comment_esc_len); php_wddx_add_chunk_static(packet, WDDX_COMMENT_E); php_wddx_add_chunk_static(packet, WDDX_HEADER_E); efree(comment_esc); } else { ``` ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=72142&edit=1

« previous php.bugs (#202727) next »