Bug #70213 [Opn->Csd]: Unserialize context shared on double class lookup
| From: | nikic@php.net | Date: | Sun, 01 Jan 2017 13:14:36 +0000 |
| Subject: | Bug #70213 [Opn->Csd]: Unserialize context shared on double class lookup | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-206281@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=70213&edit=1
ID: 70213
Updated by: nikic@php.net
Reported by: taoguangchen at icloud dot com
Summary: Unserialize context shared on double class lookup
-Status: Open
+Status: Closed
Type: Bug
Package: *General Issues
Operating System: *
PHP Version: 5.4.44
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of nikic
Revision: http://git.php.net/?p=php-src.git;a=commit;h=a65ad951ad95944e357703caa2001f06a4225bf6
Log: FIx bug #70213
Previous Comments:
------------------------------------------------------------------------
[2017-01-01 13:08:07] nikic@php.net
Looks like the use-after-free has already been otherwise resolved in the meantime. However, we
should of course still lock the context here.
------------------------------------------------------------------------
[2015-12-08 22:26:17] yohgaki@php.net
@stas
It seems proposed patch is applicable to 5.6/7.0. Are you going to merge the patch or it's not
needed for 5.6/7.0?
------------------------------------------------------------------------
[2015-08-16 22:44:38] stas@php.net
This exploit seems to require specially crafted code unlikely to be encountered in real
applications. As such, doesn't look like a security issue.
------------------------------------------------------------------------
[2015-08-08 10:56:11] taoguangchen at icloud dot com
previous PoC is work but some code is not required, so i update a new PoC:
```
ini_set('unserialize_callback_func', 'evil');
function evil() {
function __autoload($arg) {
$str = 'a:1:{i:0;i:1';
unserialize($str);
}
}
$exploit = 'a:2:{i:0;O:4:"evil":0:{}i:1;R:4;}';
$data = unserialize($exploit);
for ($i = 0; $i < 5; $i++) {
$v[$i] = 'hi'.$i;
}
var_dump($data);
```
------------------------------------------------------------------------
[2015-08-08 10:24:20] taoguangchen at icloud dot com
the patch for 5.4 series (maybe work on 5.5 and 5.6 series):
diff --git a/php-5.4.44/var_unserializer.c b/php-5.4.44-fixed/var_unserializer.c
index 8c4e629..bb35ba8 100644
--- a/php-5.4.43/var_unserializer.c
+++ b/php-5.4.43-fixed/var_unserializer.c
@@ -728,6 +728,7 @@ yy20:
}
/* The callback function may have defined the class */
+ BG(serialize_lock)++;
if (zend_lookup_class(class_name, len2, &pce TSRMLS_CC) == SUCCESS) {
ce = *pce;
} else {
@@ -735,6 +736,7 @@ yy20:
incomplete_class = 1;
ce = PHP_IC_ENTRY;
}
+ BG(serialize_lock)--;
zval_ptr_dtor(&user_func);
zval_ptr_dtor(&arg_func_name);
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=70213
--
Edit this bug report at https://bugs.php.net/bug.php?id=70213&edit=1