Bug #71606 [Ver->Csd]: Segmentation fault mb_strcut with HTML-ENTITIES encoding

From: Date: Sun, 23 Jul 2017 10:23:05 +0000
Subject: Bug #71606 [Ver->Csd]: Segmentation fault mb_strcut with HTML-ENTITIES encoding
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-210226@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71606&edit=1 ID: 71606 Updated by: nikic@php.net Reported by: imbolk at gmail dot com Summary: Segmentation fault mb_strcut with HTML-ENTITIES encoding -Status: Verified +Status: Closed Type: Bug Package: mbstring related Operating System: Linux PHP Version: 5.6.18 Block user comment: N Private report: N New Comment: Automatic comment on behalf of cmb Revision: http://git.php.net/?p=php-src.git;a=commit;h=418da85f1528172fb9df376c17f0fd79faf4aebf Log: Fix #71606: Segmentation fault mb_strcut with HTML-ENTITIES Previous Comments: ------------------------------------------------------------------------ [2016-11-28 10:14:23] cmb@php.net It seems that *every* time mb_strcut() is called with $encoding = 'HTML-ENTITIES', there will be double-frees. I can't assess the severity of these double-frees (might be harmless in all cases). ------------------------------------------------------------------------ [2016-11-27 22:59:51] stas@php.net I don't see how this can be exploitable, could you explain? ------------------------------------------------------------------------ [2016-11-27 14:20:03] kalle@php.net Re-assign since hirokawa doesn't have security permissions ------------------------------------------------------------------------ [2016-07-30 22:41:41] cmb@php.net The segfault[1] is caused by double frees in mbfl_strcut()[2] where filters are copied to backups. However, the HTML decoding filter uses the opaque member of mbfl_convert_filter[3] as buffer, so this buffer is later freed multiple times, because there is no proper copy constructor[4] defined. The attached patch solves this issue for PHP-5.6 (merging upward till master doesn't conflict). A respective fix should also be applied to <https://github.com/moriyoshi/libmbfl>. This issue might be exploitable, so I'm switching to sec bug. [1] With a debug build invalid frees are reported by ZendMM. [2] <https://github.com/php/php-src/blob/PHP-7.0.8/ext/mbstring/libmbfl/mbfl/mbfilter.c#L1716> [3] <https://github.com/php/php-src/blob/PHP-7.0.8/ext/mbstring/libmbfl/mbfl/mbfl_convert.h#L56> [4] <https://github.com/php/php-src/blob/PHP-7.0.8/ext/mbstring/libmbfl/mbfl/mbfl_convert.h#L66> ------------------------------------------------------------------------ [2016-07-30 22:41:24] cmb@php.net The following patch has been added/updated: Patch Name: fix-71606 Revision: 1469918484 URL: https://bugs.php.net/patch-display.php?bug=71606&patch=fix-71606&revision=1469918484 ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=71606 -- Edit this bug report at https://bugs.php.net/bug.php?id=71606&edit=1

« previous php.bugs (#210226) next »