Sec Bug->Bug #73559 [Opn]: output_add_rewrite_var null dereference

From: Date: Fri, 18 Nov 2016 14:39:17 +0000
Subject: Sec Bug->Bug #73559 [Opn]: output_add_rewrite_var null dereference
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-205458@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73559&edit=1 ID: 73559 Updated by: krakjoe@php.net Reported by: fernando at null-life dot com Summary: output_add_rewrite_var null dereference Status: Open -Type: Security +Type: Bug Package: Output Control Operating System: Windows PHP Version: 7.0.13 Block user comment: N Private report: Y New Comment: This issue does not meet the criteria to be considered a security issue. Please review: https://wiki.php.net/security Previous Comments: ------------------------------------------------------------------------ [2016-11-18 03:18:17] fernando at null-life dot com Description: ------------ if the supplied value parameter is too big, output_add_rewrite_var will cause an exception with a null dereference. Debugging output comes from an older PHP 7.0.10 release but I've checked it also affects current 7.0.13 static void php_url_scanner_output_handler(char *output, size_t output_len, char **handled_output, size_t *handled_output_len, int mode) { size_t len; --> if (ZSTR_LEN(BG(url_adapt_state_ex).url_app.s) != 0) { *handled_output = url_adapt_ext(output, output_len, &len, (zend_bool) (mode & (PHP_OUTPUT_HANDLER_END | PHP_OUTPUT_HANDLER_CONT | PHP_OUTPUT_HANDLER_FLUSH | PHP_OUTPUT_HANDLER_FINAL) ? 1 : 0)); if (sizeof(uint) < sizeof(size_t)) { if (len > UINT_MAX) len = UINT_MAX; } *handled_output_len = len; } else if (ZSTR_LEN(BG(url_adapt_state_ex).url_app.s) == 0) { url_adapt_state_ex_t *ctx = &BG(url_adapt_state_ex); if (ctx->buf.s && ZSTR_LEN(ctx->buf.s)) { smart_str_append(&ctx->result, ctx->buf.s); smart_str_appendl(&ctx->result, output, output_len); *handled_output = estrndup(ZSTR_VAL(ctx->result.s), ZSTR_LEN(ctx->result.s)); *handled_output_len = ZSTR_LEN(ctx->buf.s) + output_len; smart_str_free(&ctx->buf); smart_str_free(&ctx->result); } else { *handled_output = estrndup(output, *handled_output_len = output_len); } } else { *handled_output = NULL; } } Test script: --------------- <?php ini_set('memory_limit', -1); $v1="test"; $v2=str_repeat("a", 192000000); output_add_rewrite_var($v1,$v2); Expected result: ---------------- No crash Actual result: -------------- (910.1a78): Access violation - code c0000005 (first chance) First chance exceptions are reported before any exception handling. This exception may be expected and handled. 0:000:x86> r eax=00000000 ebx=00000023 ecx=50a36dd0 edx=04000000 esi=0928f2a0 edi=50a36dd0 eip=50a36dd6 esp=0928f254 ebp=0928f32c iopl=0 nv up ei pl zr na pe cy cs=0023 ss=002b ds=002b es=002b fs=0053 gs=002b efl=00010247 php7!php_url_scanner_output_handler+0x6: 50a36dd6 83780c00 cmp dword ptr [eax+0Ch],0 ds:002b:0000000c=???????? HostMachine\HostUser Executing Processor Architecture is x86 Debuggee is in User Mode Debuggee is a live user mode debugging session on the local machine Event Type: Exception Exception Faulting Address: 0xc First Chance Exception Type: STATUS_ACCESS_VIOLATION (0xC0000005) Exception Sub-Type: Read Access Violation Faulting Instruction:50a36dd6 cmp dword ptr [eax+0ch],0 Basic Block: 50a36dd6 cmp dword ptr [eax+0ch],0 Tainted Input operands: 'eax' 50a36dda je php7!php_url_scanner_output_handler+0x3e (50a36e0e) Tainted Input operands: 'ZeroFlag' Exception Hash (Major/Minor): 0x4c62c173.0xc2bad5bd Hash Usage : Stack Trace: Major+Minor : php7!php_url_scanner_output_handler+0x6 Major+Minor : php7!php_output_handler_compat_func+0x4e Major+Minor : php7!php_output_end_all+0x314 Major+Minor : php7!php_request_shutdown+0x101 Major+Minor : php!do_cli+0xdd9 Minor : php!main+0x44e Minor : php!__scrt_common_main_seh+0xf9 Minor : KERNEL32!BaseThreadInitThunk+0x24 Minor : ntdll_773e0000!__RtlUserThreadStart+0x2f Minor : ntdll_773e0000!_RtlUserThreadStart+0x1b Instruction Address: 0x0000000050a36dd6 Source File: c:\php-sdk\php70\vc14\x86\php-7.0.10rc1\ext\standard\url_scanner_ex.re Source Line: 469 ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=73559&edit=1

« previous php.bugs (#205458) next »