Bug #73361 [Fbk->Asn]: Out-of-bounds reads issue of php 5.6.27

From: Date: Wed, 26 Oct 2016 00:57:46 +0000
Subject: Bug #73361 [Fbk->Asn]: Out-of-bounds reads issue of php 5.6.27
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-205013@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73361&edit=1

 ID:                 73361
 User updated by:    271193918 at qq dot com
 Reported by:        271193918 at qq dot com
 Summary:            Out-of-bounds reads issue of php 5.6.27
-Status:             Feedback
+Status:             Assigned
 Type:               Bug
 Package:            Scripting Engine problem
 Operating System:   Ubuntu 16.04 x86
 PHP Version:        5.6.27
 Assigned To:        cmb
 Block user comment: N
 Private report:     N

 New Comment:

The link to image id_000194,sig_11,src_024221+025505,op_splice,rep_2 is:

https://mega.nz/#!AxxAzCwZ!Sx6BQTyzZupL2sCeyYLK628sJChx6eN8D754zh0Xh00


Previous Comments:
------------------------------------------------------------------------
[2016-10-25 15:16:45] cmb@php.net

To be able to debug this issue we need a copy of
./crashes/fuzzer01/id_000194,sig_11,src_024221+025505,op_splice,rep_2

------------------------------------------------------------------------
[2016-10-24 06:26:58] stas@php.net

Maybe a weird parser bug, certainly not a security issue - nobody runs binary junk as PHP script.

------------------------------------------------------------------------
[2016-10-24 06:26:02] stas@php.net

Wait, I just noticed. Why you use php -c option? This makes php read exif_read_data.php as config
file and ./crashes/fuzzer01/id_000194,sig_11,src_024221+025505,op_splice,rep_2 as a script.
That's not how it's usually supposed to work.

------------------------------------------------------------------------
[2016-10-24 06:24:49] stas@php.net

I don't see any problem in the valgrind report what exactly are you reproducing? 

Also, could you provide a link to the file:
./crashes/fuzzer01/id_000194,sig_11,src_024221+025505,op_splice,rep_2

------------------------------------------------------------------------
[2016-10-24 06:22:02] 271193918 at qq dot com

If compile php 5.6.27 with Asan:

run without USE_ZEND_ALLOC=0 , test log as follows:

./php -c ./crashes/exif_read_data.php
./crashes/fuzzer01/id_000194,sig_11,src_024221+025505,op_splice,rep_2

Fatal error: Allowed memory size of 134217728 bytes exhausted at
/home/test/Desktop/php_test/php-5.6.27-gcc-Asan/Zend/zend_vm_execute.h:12902 (tried to allocate
27751964 bytes) in
/home/test/Desktop/php_test/php-5.6.27-gcc-Asan/sapi/cli/crashes/fuzzer01/id_000194,sig_11,src_024221+025505,op_splice,rep_2
on line 65
ASAN:SIGSEGV
=================================================================
==18377==ERROR: AddressSanitizer: SEGV on unknown address 0xa70bce4b (pc 0x08b06f17 bp 0xbfbf2b98 sp
0xbfbf2b70 T0)
    #0 0x8b06f16 in _zval_dtor_func
/home/test/Desktop/php_test/php-5.6.27-gcc-Asan/Zend/zend_variables.c:36
    #1 0x8aca1af in _zval_dtor
/home/test/Desktop/php_test/php-5.6.27-gcc-Asan/Zend/zend_variables.h:35
    #2 0x8aca2bd in i_zval_ptr_dtor
/home/test/Desktop/php_test/php-5.6.27-gcc-Asan/Zend/zend_execute.h:79
    #3 0x8acd46f in _zval_ptr_dtor
/home/test/Desktop/php_test/php-5.6.27-gcc-Asan/Zend/zend_execute_API.c:424
    #4 0x8b07ce6 in _zval_ptr_dtor_wrapper
/home/test/Desktop/php_test/php-5.6.27-gcc-Asan/Zend/zend_variables.c:188
    #5 0x8b40672 in i_zend_hash_bucket_delete
/home/test/Desktop/php_test/php-5.6.27-gcc-Asan/Zend/zend_hash.c:182
    #6 0x8b4082e in zend_hash_bucket_delete
/home/test/Desktop/php_test/php-5.6.27-gcc-Asan/Zend/zend_hash.c:192
    #7 0x8b4639a in zend_hash_graceful_reverse_destroy
/home/test/Desktop/php_test/php-5.6.27-gcc-Asan/Zend/zend_hash.c:613
    #8 0x8acc193 in shutdown_executor
/home/test/Desktop/php_test/php-5.6.27-gcc-Asan/Zend/zend_execute_API.c:244
    #9 0x8b0dc11 in zend_deactivate /home/test/Desktop/php_test/php-5.6.27-gcc-Asan/Zend/zend.c:960
    #10 0x89a6b76 in php_request_shutdown
/home/test/Desktop/php_test/php-5.6.27-gcc-Asan/main/main.c:1899
    #11 0x8d6e3d9 in do_cli /home/test/Desktop/php_test/php-5.6.27-gcc-Asan/sapi/cli/php_cli.c:1181
    #12 0x8d6f0bd in main /home/test/Desktop/php_test/php-5.6.27-gcc-Asan/sapi/cli/php_cli.c:1382
    #13 0xb6ba3636 in __libc_start_main (/lib/i386-linux-gnu/libc.so.6+0x18636)
    #14 0x8067730  (/home/test/Desktop/php_test/php-5.6.27-gcc-Asan/sapi/cli/php+0x8067730)

AddressSanitizer can not provide additional info.
SUMMARY: AddressSanitizer: SEGV
/home/test/Desktop/php_test/php-5.6.27-gcc-Asan/Zend/zend_variables.c:36 _zval_dtor_func
==18377==ABORTING

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=73361


--
Edit this bug report at https://bugs.php.net/bug.php?id=73361&edit=1


Thread (1 message)

  • 271193918 at qq dot com
  • Unknown Message
    • 271193918 at qq dot com
« previous php.bugs (#205013) next »