Sec Bug->Bug #75152 [Opn]: signed integer overflow in parse_iv (ext/standard/var_unserializer.c:339)

From: Date: Mon, 11 Sep 2017 04:45:24 +0000
Subject: Sec Bug->Bug #75152 [Opn]: signed integer overflow in parse_iv (ext/standard/var_unserializer.c:339)
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-211050@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=75152&edit=1 ID: 75152 Updated by: laruence@php.net Reported by: geeknik at protonmail dot ch Summary: signed integer overflow in parse_iv (ext/standard/var_unserializer.c:339) Status: Open -Type: Security +Type: Bug Package: Reproducible crash Operating System: Ubuntu 16 x64 PHP Version: 7.1.9 Block user comment: N Private report: Y New Comment: according to https://wiki.php.net/security?s[]=security&s[]=bug "requires invocation of functions with specific arguments, which may be valid but are obviously malicious" this should not be a security bug. Previous Comments: ------------------------------------------------------------------------ [2017-09-02 20:06:48] geeknik at protonmail dot ch Description: ------------ Triggered during AFL fuzzing. Only tested against 7.1.8 and 7.1.9. If we set USE_ZEND_ALLOC=0 the signed integer overflow remains, but the memory allocation error goes away. Test script: --------------- echo -ne 'o:200000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000040000000:"' | UBSAN_OPTIONS=print_stacktrace=1 ~/! php-7.1.9/sapi/cli/php -r 'unserialize(file_get_contents("php://stdin"));' Actual result: -------------- /root/php-7.1.9/ext/standard/var_unserializer.c:339:20: runtime error: signed integer overflow: 2000000000000000000 * 10 cannot be represented in type 'long' #0 0x11cef10 in parse_iv2 /root/php-7.1.9/ext/standard/var_unserializer.c:339:20 #1 0x11cef10 in object_common1 /root/php-7.1.9/ext/standard/var_unserializer.c:507 #2 0x11c935c in php_var_unserialize_internal /root/php-7.1.9/ext/standard/var_unserializer.c:1372:13 #3 0x118f3fd in zif_unserialize /root/php-7.1.9/ext/standard/var.c:1114:7 #4 0x16b6789 in ZEND_DO_ICALL_SPEC_RETVAL_UNUSED_HANDLER /root/php-7.1.9/Zend/zend_vm_execute.h:628:2 #5 0x156d6f3 in execute_ex /root/php-7.1.9/Zend/zend_vm_execute.h:432:7 #6 0x156e2ef in zend_execute /root/php-7.1.9/Zend/zend_vm_execute.h:474:2 #7 0x13d5845 in zend_eval_stringl /root/php-7.1.9/Zend/zend_execute_API.c:1120:4 #8 0x13d617b in zend_eval_stringl_ex /root/php-7.1.9/Zend/zend_execute_API.c:1161:11 #9 0x13d617b in zend_eval_string_ex /root/php-7.1.9/Zend/zend_execute_API.c:1172 #10 0x17bb258 in do_cli /root/php-7.1.9/sapi/cli/php_cli.c:1024:8 #11 0x17b8f40 in main /root/php-7.1.9/sapi/cli/php_cli.c:1381:18 #12 0x7fd3d03a83f0 in __libc_start_main /build/glibc-mXZSwJ/glibc-2.24/csu/../csu/libc-start.c:291 #13 0x43ab99 in _start (/root/php-7.1.9/sapi/cli/php+0x43ab99) SUMMARY: UndefinedBehaviorSanitizer: undefined-behavior /root/php-7.1.9/ext/standard/var_unserializer.c:339:20 in Fatal error: Allowed memory size of 134217728 bytes exhausted (tried to allocate 2415919104 bytes) in Command line code on line 1 ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=75152&edit=1

« previous php.bugs (#211050) next »