Sec Bug->Bug #73540 [Opn]: Invalid memory access in zif_create_function
| From: | stas@php.net | Date: | Wed, 16 Nov 2016 22:01:09 +0000 |
| Subject: | Sec Bug->Bug #73540 [Opn]: Invalid memory access in zif_create_function | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-205423@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=73540&edit=1
ID: 73540
Updated by: stas@php.net
Reported by: ahihibughunter at gmail dot com
Summary: Invalid memory access in zif_create_function
Status: Open
-Type: Security
+Type: Bug
Package: Unknown/Other Function
Operating System: ALL
PHP Version: 5.6.28
Block user comment: N
Private report: Y
New Comment:
Not a security issue.
Previous Comments:
------------------------------------------------------------------------
[2016-11-16 11:12:40] ahihibughunter at gmail dot com
Description:
------------
In function zif_create_function
ZEND_FUNCTION(create_function)
{
....
eval_code[eval_code_length++] = ')';
eval_code[eval_code_length++] = '{';
memcpy(eval_code + eval_code_length, function_code, function_code_len);
eval_code_length += function_code_len;
eval_code[eval_code_length++] = '}'; <- crashed here
eval_code[eval_code_length] = '\0';
.....
}
length of eval_code increate without check it value cause php5 crash
Test script:
---------------
<?php
ini_set('memory_limit', -1);
$z = str_repeat('a',0x7fffffff);
var_dump( uasort($array_arg, create_function('x, x',$z) ) );
?>
Expected result:
----------------
No crash
Actual result:
--------------
$ gdb ../../../php5new/php-src-PHP-5.6.28/sapi/cli/php
GNU gdb (Ubuntu 7.11.1-0ubuntu1~16.04) 7.11.1
.................
(gdb) r test.php
Starting program: /home/zx/zx/php/php5new/php-src-PHP-5.6.28/sapi/cli/php test.php
[Thread debugging using libthread_db enabled]
Using host libthread_db library "/lib/x86_64-linux-gnu/libthread_db.so.1".
Program received signal SIGSEGV, Segmentation fault.
0x0000000000adff8e in zif_create_function (ht=2, return_value=0x7ffff7fb5bc0,
return_value_ptr=0x7ffff7f7a238, this_ptr=0x0, return_value_used=1)
at /home/zx/zx/php/php5new/php-src-PHP-5.6.28/Zend/zend_builtin_functions.c:1826
1826 eval_code[eval_code_length++] = '}';
(gdb) bt
#0 0x0000000000adff8e in zif_create_function (ht=2, return_value=0x7ffff7fb5bc0,
return_value_ptr=0x7ffff7f7a238, this_ptr=0x0, return_value_used=1)
at /home/zx/zx/php/php5new/php-src-PHP-5.6.28/Zend/zend_builtin_functions.c:1826
#1 0x0000000000b0bbaa in zend_do_fcall_common_helper_SPEC (execute_data=0x7ffff7f7a2b0) at
/home/zx/zx/php/php5new/php-src-PHP-5.6.28/Zend/zend_vm_execute.h:558
#2 0x0000000000b116d5 in ZEND_DO_FCALL_SPEC_CONST_HANDLER (execute_data=0x7ffff7f7a2b0) at
/home/zx/zx/php/php5new/php-src-PHP-5.6.28/Zend/zend_vm_execute.h:2602
#3 0x0000000000b0b212 in execute_ex (execute_data=0x7ffff7f7a2b0) at
/home/zx/zx/php/php5new/php-src-PHP-5.6.28/Zend/zend_vm_execute.h:363
#4 0x0000000000b0b299 in zend_execute (op_array=0x7ffff7fb5348) at
/home/zx/zx/php/php5new/php-src-PHP-5.6.28/Zend/zend_vm_execute.h:388
#5 0x0000000000ac3c49 in zend_execute_scripts (type=8, retval=0x0, file_count=3) at
/home/zx/zx/php/php5new/php-src-PHP-5.6.28/Zend/zend.c:1341
#6 0x0000000000a24d6c in php_execute_script (primary_file=0x7fffffffc9f0) at
/home/zx/zx/php/php5new/php-src-PHP-5.6.28/main/main.c:2613
#7 0x0000000000b80a61 in do_cli (argc=2, argv=0x147a670) at
/home/zx/zx/php/php5new/php-src-PHP-5.6.28/sapi/cli/php_cli.c:998
#8 0x0000000000b81dc4 in main (argc=2, argv=0x147a670) at
/home/zx/zx/php/php5new/php-src-PHP-5.6.28/sapi/cli/php_cli.c:1382
(gdb) print eval_code_length
$1 = -2147483619
(gdb)
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=73540&edit=1