Sec Bug->Bug #75152 [Opn]: signed integer overflow in parse_iv (ext/standard/var_unserializer.c:339)
| From: | laruence@php.net | Date: | Mon, 11 Sep 2017 04:45:24 +0000 |
| Subject: | Sec Bug->Bug #75152 [Opn]: signed integer overflow in parse_iv (ext/standard/var_unserializer.c:339) | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-211050@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=75152&edit=1
ID: 75152
Updated by: laruence@php.net
Reported by: geeknik at protonmail dot ch
Summary: signed integer overflow in parse_iv
(ext/standard/var_unserializer.c:339)
Status: Open
-Type: Security
+Type: Bug
Package: Reproducible crash
Operating System: Ubuntu 16 x64
PHP Version: 7.1.9
Block user comment: N
Private report: Y
New Comment:
according to https://wiki.php.net/security?s[]=security&s[]=bug
"requires invocation of functions with specific arguments, which may be valid but are obviously
malicious"
this should not be a security bug.
Previous Comments:
------------------------------------------------------------------------
[2017-09-02 20:06:48] geeknik at protonmail dot ch
Description:
------------
Triggered during AFL fuzzing. Only tested against 7.1.8 and 7.1.9. If we set USE_ZEND_ALLOC=0 the
signed integer overflow remains, but the memory allocation error goes away.
Test script:
---------------
echo -ne
'o:200000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000040000000:"'
| UBSAN_OPTIONS=print_stacktrace=1 ~/!
php-7.1.9/sapi/cli/php -r 'unserialize(file_get_contents("php://stdin"));'
Actual result:
--------------
/root/php-7.1.9/ext/standard/var_unserializer.c:339:20: runtime error: signed integer overflow:
2000000000000000000 * 10 cannot be represented in type 'long'
#0 0x11cef10 in parse_iv2 /root/php-7.1.9/ext/standard/var_unserializer.c:339:20
#1 0x11cef10 in object_common1 /root/php-7.1.9/ext/standard/var_unserializer.c:507
#2 0x11c935c in php_var_unserialize_internal
/root/php-7.1.9/ext/standard/var_unserializer.c:1372:13
#3 0x118f3fd in zif_unserialize /root/php-7.1.9/ext/standard/var.c:1114:7
#4 0x16b6789 in ZEND_DO_ICALL_SPEC_RETVAL_UNUSED_HANDLER
/root/php-7.1.9/Zend/zend_vm_execute.h:628:2
#5 0x156d6f3 in execute_ex /root/php-7.1.9/Zend/zend_vm_execute.h:432:7
#6 0x156e2ef in zend_execute /root/php-7.1.9/Zend/zend_vm_execute.h:474:2
#7 0x13d5845 in zend_eval_stringl /root/php-7.1.9/Zend/zend_execute_API.c:1120:4
#8 0x13d617b in zend_eval_stringl_ex /root/php-7.1.9/Zend/zend_execute_API.c:1161:11
#9 0x13d617b in zend_eval_string_ex /root/php-7.1.9/Zend/zend_execute_API.c:1172
#10 0x17bb258 in do_cli /root/php-7.1.9/sapi/cli/php_cli.c:1024:8
#11 0x17b8f40 in main /root/php-7.1.9/sapi/cli/php_cli.c:1381:18
#12 0x7fd3d03a83f0 in __libc_start_main
/build/glibc-mXZSwJ/glibc-2.24/csu/../csu/libc-start.c:291
#13 0x43ab99 in _start (/root/php-7.1.9/sapi/cli/php+0x43ab99)
SUMMARY: UndefinedBehaviorSanitizer: undefined-behavior
/root/php-7.1.9/ext/standard/var_unserializer.c:339:20 in
Fatal error: Allowed memory size of 134217728 bytes exhausted (tried to allocate 2415919104 bytes)
in Command line code on line 1
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=75152&edit=1