Sec Bug->Bug #73679 [Opn->Ver]: DOTNET read access violation using invalid codepage
| From: | ab@php.net | Date: | Sun, 11 Dec 2016 16:01:15 +0000 |
| Subject: | Sec Bug->Bug #73679 [Opn->Ver]: DOTNET read access violation using invalid codepage | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-205913@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=73679&edit=1
ID: 73679
Updated by: ab@php.net
Reported by: fernando at null-life dot com
Summary: DOTNET read access violation using invalid codepage
-Status: Open
+Status: Verified
-Type: Security
+Type: Bug
Package: COM related
Operating System: Windows
PHP Version: 7.0.13
-Assigned To:
+Assigned To: ab
Block user comment: N
Private report: Y
New Comment:
Nice catch, Fernando. The security impact here is quite low, i'm going to fix this as a regular
bug.
Thanks.
Previous Comments:
------------------------------------------------------------------------
[2016-12-07 20:40:35] fernando at null-life dot com
Description:
------------
Supplying -2200000000 as a codepage parameter will cause a RAV on PHP 7.0.14 x64 NTS http://windows.php.net/download/ (7.0.13 is also
affected)
Crash occur at this point
https://github.com/php/php-src/blob/PHP-7.0.14/ext/com_dotnet/com_handlers.c#L598
The data from the faulting address is later used as one or more of the arguments to a function call.
0:000> k
Child-SP RetAddr Call Site
000000e6
c231dd10 00007ff8045a42b7 php_com_dotnet!php_com_object_free_storage+0x1c
[c:\php-sdk\php70dev\vc14\x64\php-7.0.14\ext\com_dotnet\com_handlers.c @ 598]
000000e6c231dd40 00007ff8049030da php7!zend_objects_store_del+0x157
[c:\php-sdk\php70dev\vc14\x64\php-7.0.14\zend\zend_objects_api.c @ 179]
000000e6c231dfa0 00007ff8045aad00 php7!ZEND_DO_FCALL_SPEC_HANDLER+0x35ec5a
[c:\php-sdk\php70dev\vc14\x64\php-7.0.14\zend\zend_vm_execute.h @ 920]
000000e6c231e010 00007ff8045cd53c php7!execute_ex+0x70
[c:\php-sdk\php70dev\vc14\x64\php-7.0.14\zend\zend_vm_execute.h @ 417]
000000e6c231e090 00007ff8045cd329 php7!zend_execute+0x16c
[c:\php-sdk\php70dev\vc14\x64\php-7.0.14\zend\zend_vm_execute.h @ 459]
000000e6c231e0d0 00007ff8045cd197 php7!zend_execute_scripts+0x119
[c:\php-sdk\php70dev\vc14\x64\php-7.0.14\zend\zend.c @ 1438]
000000e6c231e150 00007ff708bc1c12 php7!php_execute_script+0x477
[c:\php-sdk\php70dev\vc14\x64\php-7.0.14\main\main.c @ 2494]
000000e6c231f5f0 00007ff708bc1483 php!do_cli+0x692
[c:\php-sdk\php70dev\vc14\x64\php-7.0.14\sapi\cli\php_cli.c @ 975]
000000e6c231fb50 00007ff708bc2629 php!main+0x3d3
[c:\php-sdk\php70dev\vc14\x64\php-7.0.14\sapi\cli\php_cli.c @ 1344]
000000e6c231fd40 00007ff82e3313d2 php!__scrt_common_main_seh+0x11d
[f:\dd\vctools\crt\vcstartup\src\startup\exe_common.inl @ 253]
000000e6c231fd80 00007ff82f6c54e4 KERNEL32!BaseThreadInitThunk+0x22
000000e6c231fdb0 0000000000000000 ntdll!RtlUserThreadStart+0x34
Test script:
---------------
<?php
$stack = new DOTNET("mscorlib", "System.Collections.Stack", -2200000000);
$stack->Push(".Net");
$stack->Push("Hello ");
echo $stack->Pop() . $stack->Pop();
Expected result:
----------------
No crash
Actual result:
--------------
Exception Faulting Address: 0xffffffff
First Chance Exception Type: STATUS_ACCESS_VIOLATION (0xC0000005)
Exception Sub-Type: Read Access Violation
Faulting Instruction:00007ff8`1df3541c mov rax,qword ptr [rdi]
Basic Block:
00007ff8`1df3541c mov rax,qword ptr [rdi]
Tainted Input operands: 'rdi'
00007ff8`1df3541f mov rbx,qword ptr [rax+10h]
Tainted Input operands: 'rax'
00007ff8`1df35423 mov rcx,rbx
Tainted Input operands: 'rbx'
00007ff81df35426 call qword ptr [php_com_dotnet!__guard_check_icall_fptr
(00007ff81df3f688)]
Tainted Input operands: 'rcx'
Exception Hash (Major/Minor): 0x7765425b.0x5abaeb24
Hash Usage : Stack Trace:
Major+Minor : php_com_dotnet!php_com_object_free_storage+0x1c
Major+Minor : php7!zend_objects_store_del+0x157
Major+Minor : php7!ZEND_DO_FCALL_SPEC_HANDLER+0x35ec5a
Major+Minor : php7!execute_ex+0x70
Major+Minor : php7!zend_execute+0x16c
Minor : php7!zend_execute_scripts+0x119
Minor : php7!php_execute_script+0x477
Minor : php!do_cli+0x692
Minor : php!main+0x3d3
Minor : php!__scrt_common_main_seh+0x11d
Minor : KERNEL32!BaseThreadInitThunk+0x22
Minor : ntdll!RtlUserThreadStart+0x34
Instruction Address: 0x00007ff81df3541c
Source File: c:\php-sdk\php70dev\vc14\x64\php-7.0.14\ext\com_dotnet\com_handlers.c
Source Line: 598
Description: Data from Faulting Address is used as one or more arguments in a subsequent Function
Call
Short Description: TaintedDataPassedToFunction
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=73679&edit=1