Sec Bug->Bug #76244 [Opn]: A stack overflow vulnerability exist (most likely) in the isSet function

From: Date: Mon, 23 Apr 2018 03:34:29 +0000
Subject: Sec Bug->Bug #76244 [Opn]: A stack overflow vulnerability exist (most likely) in the isSet function
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-214834@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76244&edit=1

 ID:                 76244
 Updated by:         stas@php.net
 Reported by:        daniel dot teuchert at rub dot de
 Summary:            A stack overflow vulnerability exist (most likely)
                     in the isSet function
 Status:             Open
-Type:               Security
+Type:               Bug
 Package:            *Programming Data Structures
 Operating System:   Linux 4.6.2
 PHP Version:        7.2.4
 Block user comment: N
 Private report:     Y

 New Comment:

Not a security issue, please see https://wiki.php.net/security


Previous Comments:
------------------------------------------------------------------------
[2018-04-22 22:16:08] cmb@php.net

This does not look like a security issue, since checking so many
variables in a single isset() does not appear to be of any
practical purpose.

------------------------------------------------------------------------
[2018-04-20 11:12:10] daniel dot teuchert at rub dot de

Description:
------------
Calling isSet with too many parameters causes a stack overflow.
Executing the test script results in a stack overflow.
The produced ASAN output can be found here: https://github.com/pnoltof/php_bug/blob/master/ASAN_output.txt
An attacker can possibly use this flaw to execute arbitrary code.

Steps to reproduce:
Build latest php version (compile with ASAN)
Donwload PoC file called "stack_overflow" (see Test script)
Execute binary file in $WORKDIR/php-7.2.4/sapi/cli/:
$WORKDIR/php-7.2.4/sapi/cli/php stack_overflow

I was not able to reproduce this behavior when debugging with gdb.

Test script:
---------------
PoC file can be found here: https://github.com/pnoltof/php_bug/blob/master/stack_overflow



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=76244&edit=1


Thread (1 message)

  • stas@php.net
  • Unknown Message
    • stas@php.net
« previous php.bugs (#214834) next »