Edit report at https://bugs.php.net/bug.php?id=75934&edit=1
ID: 75934
User updated by: zhihua dot yao at dbappsecurity dot com dot cn
Reported by: zhihua dot yao at dbappsecurity dot com dot cn
Summary: Out of Bound in sodium_pad
Status: Assigned
Type: Bug
Package: Reproducible crash
PHP Version: 7.2.2
Assigned To: jedisct1
Block user comment: N
Private report: N
New Comment:
Yes,Ubuntu 14.04 x86
Previous Comments:
------------------------------------------------------------------------
[2018-04-27 13:43:14] jedisct1@php.net
What system is that on? Is it a 32 bit system?
------------------------------------------------------------------------
[2018-04-27 12:05:17] cmb@php.net
On a quick glance, the check blocksize > SIZE_MAX[1] looks
fishy. Frank, could you please have a look at this issue?
[1] <https://github.com/php/php-src/blob/PHP-7.2.2/ext/sodium/libsodium.c#L3386>
------------------------------------------------------------------------
[2018-04-27 02:41:36] zhihua dot yao at dbappsecurity dot com dot cn
Any update?Security Issue?
------------------------------------------------------------------------
[2018-02-08 07:11:40] zhihua dot yao at dbappsecurity dot com dot cn
Description:
------------
I do not know where the problem is.
Test script:
---------------
<?php
ini_set('memory_limit',-1);
$str=str_repeat("A",0x7fffffff);
sodium_pad($str,0x7fffffff);
Actual result:
--------------
Legend: code, data, rodata, value
Stopped reason: SIGSEGV
0x08253de4 in zif_sodium_pad (execute_data=0xb781a0a0,
return_value=0xbfffbbf0)
at /home/hjy/Desktop/php-7.2.2/ext/sodium/libsodium.c:3406
3406 ZSTR_VAL(padded)[j] = unpadded[i];
gdb-peda$ bt
#0 0x08253de4 in zif_sodium_pad (execute_data=0xb781a0a0,
return_value=0xbfffbbf0)
at /home/hjy/Desktop/php-7.2.2/ext/sodium/libsodium.c:3406
#1 0x083f7d04 in ZEND_DO_ICALL_SPEC_RETVAL_UNUSED_HANDLER ()
at /home/hjy/Desktop/php-7.2.2/Zend/zend_vm_execute.h:573
#2 execute_ex (ex=0x37400010)
at /home/hjy/Desktop/php-7.2.2/Zend/zend_vm_execute.h:59731
#3 0x084002b4 in zend_execute (op_array=op_array@entry=0xb787c000,
return_value=return_value@entry=0x0)
at /home/hjy/Desktop/php-7.2.2/Zend/zend_vm_execute.h:63760
#4 0x08363690 in zend_execute_scripts (type=type@entry=0x8,
retval=retval@entry=0x0, file_count=file_count@entry=0x3)
at /home/hjy/Desktop/php-7.2.2/Zend/zend.c:1496
#5 0x0830344e in php_execute_script (
primary_file=primary_file@entry=0xbfffdee4)
at /home/hjy/Desktop/php-7.2.2/main/main.c:2590
#6 0x084026db in do_cli (argc=argc@entry=0x2,
argv=argv@entry=0x8af8000)
at /home/hjy/Desktop/php-7.2.2/sapi/cli/php_cli.c:1011
#7 0x08071637 in main (argc=0x2, argv=0x8af8000)
at /home/hjy/Desktop/php-7.2.2/sapi/cli/php_cli.c:1404
#8 0xb7c08af3 in __libc_start_main (main=0x8071160 <main>, argc=0x2,
argv=0xbffff194, init=0x840a390 <__libc_csu_init>,
fini=0x840a400 <__libc_csu_fini>, rtld_fini=0xb7fed2d0 <_dl_fini>,
stack_end=0xbffff18c) at libc-start.c:287
#9 0x080716c2 in _start ()
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=75934&edit=1