Sec Bug->Bug #71606 [Ver]: Segmentation fault mb_strcut + mb_list_encodings
| From: | nikic@php.net | Date: | Sun, 23 Jul 2017 10:11:23 +0000 |
| Subject: | Sec Bug->Bug #71606 [Ver]: Segmentation fault mb_strcut + mb_list_encodings | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-210223@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=71606&edit=1
ID: 71606
Updated by: nikic@php.net
Reported by: imbolk at gmail dot com
Summary: Segmentation fault mb_strcut + mb_list_encodings
Status: Verified
-Type: Security
+Type: Bug
Package: mbstring related
Operating System: Linux
PHP Version: 5.6.18
Block user comment: N
Private report: Y
Previous Comments:
------------------------------------------------------------------------
[2016-11-28 10:14:23] cmb@php.net
It seems that *every* time mb_strcut() is called with $encoding =
'HTML-ENTITIES', there will be double-frees. I can't assess the
severity of these double-frees (might be harmless in all cases).
------------------------------------------------------------------------
[2016-11-27 22:59:51] stas@php.net
I don't see how this can be exploitable, could you explain?
------------------------------------------------------------------------
[2016-11-27 14:20:03] kalle@php.net
Re-assign since hirokawa doesn't have security permissions
------------------------------------------------------------------------
[2016-07-30 22:41:41] cmb@php.net
The segfault[1] is caused by double frees in mbfl_strcut()[2]
where filters are copied to backups. However, the HTML decoding
filter uses the
opaque member of mbfl_convert_filter[3] as
buffer, so this buffer is later freed multiple times, because
there is no proper copy constructor[4] defined.
The attached patch solves this issue for PHP-5.6 (merging upward
till master doesn't conflict). A respective fix should also be
applied to <https://github.com/moriyoshi/libmbfl>.
This issue might be exploitable, so I'm switching to sec bug.
[1] With a debug build invalid frees are reported by ZendMM.
[2] <https://github.com/php/php-src/blob/PHP-7.0.8/ext/mbstring/libmbfl/mbfl/mbfilter.c#L1716>
[3] <https://github.com/php/php-src/blob/PHP-7.0.8/ext/mbstring/libmbfl/mbfl/mbfl_convert.h#L56>
[4] <https://github.com/php/php-src/blob/PHP-7.0.8/ext/mbstring/libmbfl/mbfl/mbfl_convert.h#L66>
------------------------------------------------------------------------
[2016-07-30 22:41:24] cmb@php.net
The following patch has been added/updated:
Patch Name: fix-71606
Revision: 1469918484
URL: https://bugs.php.net/patch-display.php?bug=71606&patch=fix-71606&revision=1469918484
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=71606
--
Edit this bug report at https://bugs.php.net/bug.php?id=71606&edit=1