Edit report at https://bugs.php.net/bug.php?id=76244&edit=1
ID: 76244
Updated by: stas@php.net
Reported by: daniel dot teuchert at rub dot de
Summary: A stack overflow vulnerability exist (most likely)
in the isSet function
Status: Open
-Type: Security
+Type: Bug
Package: *Programming Data Structures
Operating System: Linux 4.6.2
PHP Version: 7.2.4
Block user comment: N
Private report: Y
New Comment:
Not a security issue, please see https://wiki.php.net/security
Previous Comments:
------------------------------------------------------------------------
[2018-04-22 22:16:08] cmb@php.net
This does not look like a security issue, since checking so many
variables in a single isset() does not appear to be of any
practical purpose.
------------------------------------------------------------------------
[2018-04-20 11:12:10] daniel dot teuchert at rub dot de
Description:
------------
Calling isSet with too many parameters causes a stack overflow.
Executing the test script results in a stack overflow.
The produced ASAN output can be found here: https://github.com/pnoltof/php_bug/blob/master/ASAN_output.txt
An attacker can possibly use this flaw to execute arbitrary code.
Steps to reproduce:
Build latest php version (compile with ASAN)
Donwload PoC file called "stack_overflow" (see Test script)
Execute binary file in $WORKDIR/php-7.2.4/sapi/cli/:
$WORKDIR/php-7.2.4/sapi/cli/php stack_overflow
I was not able to reproduce this behavior when debugging with gdb.
Test script:
---------------
PoC file can be found here: https://github.com/pnoltof/php_bug/blob/master/stack_overflow
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=76244&edit=1