Sec Bug->Bug #73095 [Csd]: null ptr deref, segfault in zend_std_write_property: zend_object_handlers.c:585
| From: | stas@php.net | Date: | Mon, 13 Feb 2017 01:19:29 +0000 |
| Subject: | Sec Bug->Bug #73095 [Csd]: null ptr deref, segfault in zend_std_write_property: zend_object_handlers.c:585 | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-207331@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=73095&edit=1
ID: 73095
Updated by: stas@php.net
Reported by: brian dot carpenter at gmail dot com
Summary: null ptr deref, segfault in zend_std_write_property:
zend_object_handlers.c:585
Status: Closed
-Type: Security
+Type: Bug
Package: Reproducible crash
Operating System: Debian 8 x64
PHP Version: 5.6.25
-Assigned To:
+Assigned To: stas
Block user comment: N
Private report: Y
Previous Comments:
------------------------------------------------------------------------
[2016-09-15 18:30:43] brian dot carpenter at gmail dot com
Fixed in git.
------------------------------------------------------------------------
[2016-09-15 17:58:43] brian dot carpenter at gmail dot com
Description:
------------
The linked script triggers a null ptr deref and segfault in PHP 5.6.25 x64. Found via AFL + ASAN.
Test script:
---------------
https://dl.dropboxusercontent.com/u/6088006/php/segfault_zend_std_write_property
Expected result:
----------------
No crash.
Actual result:
--------------
==3861==ERROR: AddressSanitizer: SEGV on unknown address 0x000000000000 (pc 0x0000019c7ce3 sp
0x7ffd4782be60 bp 0x7ffd4782c110 T0)
#0 0x19c7ce2 in zend_std_write_property /home/geeknik/php-5.6.25/Zend/zend_object_handlers.c:585
#1 0x1e00e75 in zend_assign_to_object /home/geeknik/php-5.6.25/Zend/zend_execute.c:769
#2 0x1e00e75 in ZEND_ASSIGN_OBJ_SPEC_UNUSED_CONST_HANDLER
/home/geeknik/php-5.6.25/Zend/zend_vm_execute.h:25532
#3 0x1a32883 in execute_ex /home/geeknik/php-5.6.25/Zend/zend_vm_execute.h:363
#4 0x181d11c in zend_call_function /home/geeknik/php-5.6.25/Zend/zend_execute_API.c:829
#5 0x194575a in zend_call_method /home/geeknik/php-5.6.25/Zend/zend_interfaces.c:97
#6 0x19ad045 in zend_objects_destroy_object /home/geeknik/php-5.6.25/Zend/zend_objects.c:123
#7 0x19d909c in zend_objects_store_call_destructors
/home/geeknik/php-5.6.25/Zend/zend_objects_API.c:57
#8 0x181320c in shutdown_destructors /home/geeknik/php-5.6.25/Zend/zend_execute_API.c:216
#9 0x1892043 in zend_call_destructors /home/geeknik/php-5.6.25/Zend/zend.c:944
#10 0x15ccdcc in php_request_shutdown /home/geeknik/php-5.6.25/main/main.c:1840
#11 0x1e61396 in do_cli /home/geeknik/php-5.6.25/sapi/cli/php_cli.c:1177
#12 0x457030 in main /home/geeknik/php-5.6.25/sapi/cli/php_cli.c:1378
#13 0x7f874b9efb44 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x21b44)
#14 0x457d9e (/home/geeknik/php-5.6.25/sapi/cli/php+0x457d9e)
AddressSanitizer can not provide additional info.
SUMMARY: AddressSanitizer: SEGV /home/geeknik/php-5.6.25/Zend/zend_object_handlers.c:585
zend_std_write_property
==3861==ABORTING
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=73095&edit=1