Sec Bug->Bug #73755 [Nab]: FG-VD-16-092 : Stack Corruption leading to Arbitrary Code Execution

From: Date: Tue, 20 Dec 2016 07:33:11 +0000
Subject: Sec Bug->Bug #73755 [Nab]: FG-VD-16-092 : Stack Corruption leading to Arbitrary Code Execution
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-206144@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73755&edit=1

 ID:                 73755
 Updated by:         stas@php.net
 Reported by:        kshah at fortinet dot com
 Summary:            FG-VD-16-092 : Stack Corruption leading to Arbitrary
                     Code Execution
 Status:             Not a bug
-Type:               Security
+Type:               Bug
 Package:            Arrays related
 Operating System:   Linux
 PHP Version:        master-Git-2016-12-16 (Git)
 Block user comment: N
 Private report:     N



Previous Comments:
------------------------------------------------------------------------
[2016-12-20 07:32:57] stas@php.net

Doesn't seem to be a bug then.

------------------------------------------------------------------------
[2016-12-19 08:05:34] dmitry@php.net

The crash occurs because of CPU stack overflow, caused by infinity recursion.

unset() -> offsetUnset() -> [offsetGet() -> new ArrayAccessReferenceProxy()] -> unset()

------------------------------------------------------------------------
[2016-12-16 07:21:02] kshah at fortinet dot com

The issue exists even when compiled with ASAN, Without setting the USE_ZEND_ALLOC=0 flag.

------------------------------------------------------------------------
[2016-12-16 01:58:56] kshah at fortinet dot com

Description:
------------
There exists a Stack Corruption Vulnerability leading to Arbitrary Code Execution within the latest
PHP client.

In order to reproduce this issue, please do the following.

1) Compile PHP 7.2.0 Master Git using address sanitizer and the flag USE_ZEND_ALLOC=0.

2) Run the PoC.php test script using the php cli client.

The issue exists due to the incorrect handling of the unset function.

Test script:
---------------
https://www.dropbox.com/s/kgxye17o9gixdkh/PoC.php?dl=0

Expected result:
----------------
root@kali:~/Downloads# /root/Downloads/php-src/sapi/cli/php original.php 
===ArrayOverloading===
ArrayAccessReferenceProxy::__construct(0)
ArrayAccessReferenceProxy::offsetUnset(0, name)
ArrayAccessReferenceProxy::__construct(0)
object(ArrayAccessReferenceProxy)#1 (3) {
  ["object":"ArrayAccessReferenceProxy":private]=>
  object(Peoples)#2 (1) {
    ["person"]=>
    &array(1) {
      [0]=>
      array(0) {
      }
    }
  }
  ["oarray":"ArrayAccessReferenceProxy":private]=>
  &array(1) {
    [0]=>
    array(0) {
    }
  }
  ["element":"ArrayAccessReferenceProxy":private]=>
  int(0)
}
===DONE===

Actual result:
--------------
Starting program: /root/Downloads/php-src/sapi/cli/php /root/Downloads/php-out_crashes/PoC.php
[Thread debugging using libthread_db enabled]
Using host libthread_db library "/lib/i386-linux-gnu/libthread_db.so.1".

Program received signal SIGSEGV, Segmentation fault.
0x812cd218 in i_init_execute_data (return_value=0x81a5b000, 
    op_array=0xb5a0368c, execute_data=0xb56686d0)
    at /root/Downloads/php-src/Zend/zend_execute.c:2226
2226		if (EX_CALL_INFO() & ZEND_CALL_HAS_SYMBOL_TABLE) {
#0  0x812cd218 in i_init_execute_data (return_value=0x81a5b000, 
    op_array=0xb5a0368c, execute_data=0xb56686d0)
    at /root/Downloads/php-src/Zend/zend_execute.c:2226
#1  zend_init_execute_data (
    execute_data=0x812cd1c7 <zend_init_execute_data+55>, op_array=0x81a5b000, 
    return_value=0x81a5b000)
    at /root/Downloads/php-src/Zend/zend_execute.c:2299
#2  0x00000001 in ?? ()
#3  0x812cd1c7 in zend_init_execute_data (execute_data=0xb56686d0, 
    op_array=0xb5a0368c, return_value=0xb56686c0)
    at /root/Downloads/php-src/Zend/zend_execute.c:2297
#4  0x80eb4c77 in zend_call_function (fci=0xbf800148, fci_cache=0xbf800114)
    at /root/Downloads/php-src/Zend/zend_execute_API.c:833
#5  0x8101cc66 in zend_call_method (object=0xb5683e78, obj_ce=0xb5a0342c, 
    fn_proxy=0x0, function_name=0x81899f24 "offsetget", function_name_len=9, 
    retval_ptr=0xb56686c0, param_count=1, arg1=0xb56686b0, arg2=0x0)
    at /root/Downloads/php-src/Zend/zend_interfaces.c:99
#6  0x810ba76a in zend_std_read_dimension (object=0xb5683e78, 
    offset=0xb56686b0, type=5, rv=0xb56686c0)
    at /root/Downloads/php-src/Zend/zend_object_handlers.c:792
#7  0x811b5ffd in zend_fetch_dimension_address (type=5, dim_type=6, 
    dim=<optimized out>, container=0xb5683e78, result=0xb56686c0)
    at /root/Downloads/php-src/Zend/zend_execute.c:1718
#8  zend_fetch_dimension_address_UNSET (result=0xb56686c0, 
    container_ptr=<optimized out>, dim=0xb56686b0, dim_type=6)
    at /root/Downloads/php-src/Zend/zend_execute.c:1794
#9  0x811b74fe in ZEND_FETCH_DIM_UNSET_SPEC_VAR_TMPVAR_HANDLER ()
    at /root/Downloads/php-src/Zend/zend_vm_execute.h:24951
#10 0x8126d712 in execute_ex (ex=0xb5668610)
    at /root/Downloads/php-src/Zend/zend_vm_execute.h:429
#11 0x80eb4c84 in zend_call_function (fci=0xbf800398, fci_cache=0xbf800364)
    at /root/Downloads/php-src/Zend/zend_execute_API.c:834
#12 0x8101cc66 in zend_call_method (object=0xb5668600, obj_ce=0xb5a0300c, 
    fn_proxy=0x0, function_name=0x81899f45 "offsetunset", 
    function_name_len=11, retval_ptr=0x0, param_count=1, arg1=0xb5668580, 
    arg2=0x0) at /root/Downloads/php-src/Zend/zend_interfaces.c:99
#13 0x810ba254 in zend_std_unset_dimension (object=0xb5668600, 
    offset=0xb5668580)
    at /root/Downloads/php-src/Zend/zend_object_handlers.c:1012
#14 0x8121aed7 in ZEND_UNSET_DIM_SPEC_VAR_CV_HANDLER ()
    at /root/Downloads/php-src/Zend/zend_vm_execute.h:24100
#15 0x8126d712 in execute_ex (ex=0xb5668550)
    at /root/Downloads/php-src/Zend/zend_vm_execute.h:429
Quit
Description: Possible stack corruption
Short description: PossibleStackCorruption (7/22)
Hash: 311968a4ab3347ac6bec733a47e2f47e.fe407b7ea324997767071bf04ab8a725
Exploitability Classification: EXPLOITABLE
Explanation: GDB generated an error while unwinding the stack and/or the stack contained return
addresses that were not mapped in the inferior's process address space and/or the stack pointer
is pointing to a location outside the default stack region. These conditions likely indicate stack
corruption, which is generally considered exploitable.
Other tags: DestAv (8/22), AccessViolation (21/22)


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=73755&edit=1


Thread (1 message)

  • stas@php.net
  • Unknown Message
    • stas@php.net
« previous php.bugs (#206144) next »