Sec Bug->Bug #73095 [Csd]: null ptr deref, segfault in zend_std_write_property: zend_object_handlers.c:585

From: Date: Mon, 13 Feb 2017 01:19:29 +0000
Subject: Sec Bug->Bug #73095 [Csd]: null ptr deref, segfault in zend_std_write_property: zend_object_handlers.c:585
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-207331@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73095&edit=1 ID: 73095 Updated by: stas@php.net Reported by: brian dot carpenter at gmail dot com Summary: null ptr deref, segfault in zend_std_write_property: zend_object_handlers.c:585 Status: Closed -Type: Security +Type: Bug Package: Reproducible crash Operating System: Debian 8 x64 PHP Version: 5.6.25 -Assigned To: +Assigned To: stas Block user comment: N Private report: Y Previous Comments: ------------------------------------------------------------------------ [2016-09-15 18:30:43] brian dot carpenter at gmail dot com Fixed in git. ------------------------------------------------------------------------ [2016-09-15 17:58:43] brian dot carpenter at gmail dot com Description: ------------ The linked script triggers a null ptr deref and segfault in PHP 5.6.25 x64. Found via AFL + ASAN. Test script: --------------- https://dl.dropboxusercontent.com/u/6088006/php/segfault_zend_std_write_property Expected result: ---------------- No crash. Actual result: -------------- ==3861==ERROR: AddressSanitizer: SEGV on unknown address 0x000000000000 (pc 0x0000019c7ce3 sp 0x7ffd4782be60 bp 0x7ffd4782c110 T0) #0 0x19c7ce2 in zend_std_write_property /home/geeknik/php-5.6.25/Zend/zend_object_handlers.c:585 #1 0x1e00e75 in zend_assign_to_object /home/geeknik/php-5.6.25/Zend/zend_execute.c:769 #2 0x1e00e75 in ZEND_ASSIGN_OBJ_SPEC_UNUSED_CONST_HANDLER /home/geeknik/php-5.6.25/Zend/zend_vm_execute.h:25532 #3 0x1a32883 in execute_ex /home/geeknik/php-5.6.25/Zend/zend_vm_execute.h:363 #4 0x181d11c in zend_call_function /home/geeknik/php-5.6.25/Zend/zend_execute_API.c:829 #5 0x194575a in zend_call_method /home/geeknik/php-5.6.25/Zend/zend_interfaces.c:97 #6 0x19ad045 in zend_objects_destroy_object /home/geeknik/php-5.6.25/Zend/zend_objects.c:123 #7 0x19d909c in zend_objects_store_call_destructors /home/geeknik/php-5.6.25/Zend/zend_objects_API.c:57 #8 0x181320c in shutdown_destructors /home/geeknik/php-5.6.25/Zend/zend_execute_API.c:216 #9 0x1892043 in zend_call_destructors /home/geeknik/php-5.6.25/Zend/zend.c:944 #10 0x15ccdcc in php_request_shutdown /home/geeknik/php-5.6.25/main/main.c:1840 #11 0x1e61396 in do_cli /home/geeknik/php-5.6.25/sapi/cli/php_cli.c:1177 #12 0x457030 in main /home/geeknik/php-5.6.25/sapi/cli/php_cli.c:1378 #13 0x7f874b9efb44 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x21b44) #14 0x457d9e (/home/geeknik/php-5.6.25/sapi/cli/php+0x457d9e) AddressSanitizer can not provide additional info. SUMMARY: AddressSanitizer: SEGV /home/geeknik/php-5.6.25/Zend/zend_object_handlers.c:585 zend_std_write_property ==3861==ABORTING ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=73095&edit=1

« previous php.bugs (#207331) next »