Sec Bug->Bug #73008 [Opn]: Bug #72286 is actually a gc use after free and is exploitable

From: Date: Sat, 03 Sep 2016 20:08:37 +0000
Subject: Sec Bug->Bug #73008 [Opn]: Bug #72286 is actually a gc use after free and is exploitable
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-203767@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73008&edit=1 ID: 73008 Updated by: stas@php.net Reported by: xavier dot combelle at gmail dot com Summary: Bug #72286 is actually a gc use after free and is exploitable Status: Open -Type: Security +Type: Bug Package: *General Issues Operating System: debian jessie PHP Version: 5.6.25 Block user comment: N Private report: Y Previous Comments: ------------------------------------------------------------------------ [2016-09-03 19:54:19] xavier dot combelle at gmail dot com Description: ------------ I use a fresh php just compiled for test like this ./sapi/cli/php ~/public_html/test.php It occurred to me that Bug #72286, is indeed an use after free kind of bug so could be exploitable. With a variation of Bug #72286 report, I show how the bug could lead to not intended execution. For the proof of concept I just call a method which echo "dangerous". If I don't mistake attribute change could be also obtained. Apart that the destructed object should be take in a reference cycle, and the garbage collection triggered, the only constraint I see of the proof of concept is that a target object must be created inside the destructor and the target method/attribute should be call Test script: --------------- https://gist.github.com/xcombelle/cc8c391e93d01dfe9568bf634a656767 Expected result: ---------------- not dangerous Actual result: -------------- dangerous ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=73008&edit=1

« previous php.bugs (#203767) next »