Bug #75575 [Opn->Csd]: Theoretical pointer wrapping and access-out-of-bounds in non-standard Zend code
| From: | nikic@php.net | Date: | Tue, 28 Nov 2017 22:13:32 +0000 |
| Subject: | Bug #75575 [Opn->Csd]: Theoretical pointer wrapping and access-out-of-bounds in non-standard Zend code | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-212783@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=75575&edit=1
ID: 75575
Updated by: nikic@php.net
Reported by: plebbyastian at gmail dot com
Summary: Theoretical pointer wrapping and
access-out-of-bounds in non-standard Zend code
-Status: Open
+Status: Closed
Type: Bug
Package: *General Issues
Operating System: Whatever
PHP Version: Irrelevant
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of nikita.ppv@gmail.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=5dc6392d257fa8a4c3a8938e9e0e36ae44a6834e
Log: Fixed bug #75575
Previous Comments:
------------------------------------------------------------------------
[2017-11-26 23:14:29] plebbyastian at gmail dot com
Description:
------------
The subtraction at <https://github.com/php/php-src/blob/26f8fc833b9668a8b8e14ecd7d94930146019adb/Zend/zend_operators.c#L3059>
has no guard to ensure pointer wrapping (which itself is undefined behaviour) doesn't occur.
There's an identical unguarded pointer subtraction at <https://github.com/php/php-src/blob/26f8fc833b9668a8b8e14ecd7d94930146019adb/Zend/zend_operators.c#L3093>.
Successful exploitation would result in high ranges of memory becoming accessible to the attacker,
with similar usecases to heartbleed.
Remember this when you try to argue for use of non-standard, reinvented wheels. Testing incurs a
price. As does code complexity. To put my "standardisation" rants into perspective,
here's how C11/6.5.6p8 defines PHP:
> ... If both the pointer operand and the result point to elements of the same array object, or
> one past the last element of the array object, the evaluation shall not produce an overflow;
> otherwise, the behavior is undefined. ...
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=75575&edit=1