Sec Bug->Bug #75002 [Opn]: Null Pointer Dereference in timelib_time_clone
| From: | stas@php.net | Date: | Sun, 30 Jul 2017 19:41:09 +0000 |
| Subject: | Sec Bug->Bug #75002 [Opn]: Null Pointer Dereference in timelib_time_clone | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-210420@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=75002&edit=1
ID: 75002
Updated by: stas@php.net
Reported by: zhihua dot yao at dbappsecurity dot com dot cn
Summary: Null Pointer Dereference in timelib_time_clone
Status: Open
-Type: Security
+Type: Bug
Package: SPL related
PHP Version: 5.6.31, 7.1.7
Block user comment: N
Private report: Y
Previous Comments:
------------------------------------------------------------------------
[2017-07-28 11:40:58] derick@php.net
The following patch has been added/updated:
Patch Name: date-period-ctor-75002.txt.diff
Revision: 1501242055
URL: https://bugs.php.net/patch-display.php?bug=75002&patch=date-period-ctor-75002.txt.diff&revision=1501242055
------------------------------------------------------------------------
[2017-07-28 10:44:12] derick@php.net
DatePeriod, wrapping internal structures, should not be extendable. In any case, I can reproduce
this and I'm looking at a fix right now.
------------------------------------------------------------------------
[2017-07-28 10:08:49] zhihua dot yao at dbappsecurity dot com dot cn
Description:
------------
Since the argument origts to 0, the null pointer is interpreted.
Test script:
---------------
<?php
class aaa extends DatePeriod {
public function __construct() { }
}
$start=new DateTime( '2012-08-01' );
foreach (new aaa($start) as $y){
$a=$key;
}
Expected result:
----------------
no crash
Actual result:
--------------
root@ubuntu:/home/hjy/Desktop# ./php-7.1.7/sapi/cli/php poc.php
ASAN:SIGSEGV
=================================================================
==6186==ERROR: AddressSanitizer: SEGV on unknown address 0x00000000 (pc 0x081c3fb7 sp 0xbfde97f0 bp
0xbfde9818 T0)
#0 0x81c3fb6 in memcpy /usr/include/i386-linux-gnu/bits/string3.h:51
#1 0x81c3fb6 in timelib_time_clone /home/hjy/Desktop/php-7.1.7/ext/date/lib/timelib.c:58
#2 0x80be985 in date_period_it_rewind /home/hjy/Desktop/php-7.1.7/ext/date/php_date.c:1947
#3 0xa12536a in ZEND_FE_RESET_R_SPEC_VAR_HANDLER
/home/hjy/Desktop/php-7.1.7/Zend/zend_vm_execute.h:16525
#4 0x9f38f6f in execute_ex /home/hjy/Desktop/php-7.1.7/Zend/zend_vm_execute.h:429
#5 0xa34f88b in zend_execute /home/hjy/Desktop/php-7.1.7/Zend/zend_vm_execute.h:474
#6 0x9c69108 in zend_execute_scripts /home/hjy/Desktop/php-7.1.7/Zend/zend.c:1476
#7 0x98eb275 in php_execute_script /home/hjy/Desktop/php-7.1.7/main/main.c:2537
#8 0xa35f295 in do_cli /home/hjy/Desktop/php-7.1.7/sapi/cli/php_cli.c:993
#9 0x80a8ceb in main /home/hjy/Desktop/php-7.1.7/sapi/cli/php_cli.c:1381
#10 0xb6bdca82 in __libc_start_main (/lib/i386-linux-gnu/libc.so.6+0x19a82)
#11 0x80a995f (/home/hjy/Desktop/php-7.1.7/sapi/cli/php+0x80a995f)
AddressSanitizer can not provide additional info.
SUMMARY: AddressSanitizer: SEGV /usr/include/i386-linux-gnu/bits/string3.h:51 memcpy
==6186==ABORTING
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=75002&edit=1