Sec Bug->Bug #73008 [Opn]: Bug #72286 is actually a gc use after free and is exploitable
| From: | stas@php.net | Date: | Sat, 03 Sep 2016 20:08:37 +0000 |
| Subject: | Sec Bug->Bug #73008 [Opn]: Bug #72286 is actually a gc use after free and is exploitable | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-203767@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=73008&edit=1
ID: 73008
Updated by: stas@php.net
Reported by: xavier dot combelle at gmail dot com
Summary: Bug #72286 is actually a gc use after free and is
exploitable
Status: Open
-Type: Security
+Type: Bug
Package: *General Issues
Operating System: debian jessie
PHP Version: 5.6.25
Block user comment: N
Private report: Y
Previous Comments:
------------------------------------------------------------------------
[2016-09-03 19:54:19] xavier dot combelle at gmail dot com
Description:
------------
I use a fresh php just compiled for test like this
./sapi/cli/php ~/public_html/test.php
It occurred to me that Bug #72286, is indeed an use after free kind of bug so could be exploitable.
With a variation of Bug #72286 report, I show how the bug could lead to not intended execution.
For the proof of concept I just call a method which echo "dangerous". If I don't
mistake attribute change could be also obtained.
Apart that the destructed object should be take in a reference cycle, and the garbage collection
triggered, the only constraint I see of the proof of concept is that a target object must be created
inside the destructor and the target method/attribute should be call
Test script:
---------------
https://gist.github.com/xcombelle/cc8c391e93d01dfe9568bf634a656767
Expected result:
----------------
not dangerous
Actual result:
--------------
dangerous
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=73008&edit=1