Sec Bug->Bug #73755 [Asn]: Infinite recursion within unset() leads to SEGV

From: Date: Wed, 07 Nov 2018 22:05:31 +0000
Subject: Sec Bug->Bug #73755 [Asn]: Infinite recursion within unset() leads to SEGV
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-217851@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73755&edit=1

 ID:                 73755
 Updated by:         stas@php.net
 Reported by:        kshah at fortinet dot com
 Summary:            Infinite recursion within unset() leads to SEGV
 Status:             Assigned
-Type:               Security
+Type:               Bug
 Package:            Arrays related
 Operating System:   Linux
 PHP Version:        master-Git-2016-12-16 (Git)
 Assigned To:        dmitry
 Block user comment: N
 Private report:     N



Previous Comments:
------------------------------------------------------------------------
[2018-11-01 09:41:15] ryan dot jentzsch at gmail dot com

Looks to be fixed in version 7.2.10 running this code produces:
PHP Fatal error:  Uncaught Error: Maximum function nesting level of '256' reached,
aborting!

Linux Mint 19 (Tara)
Kernel 4.19

------------------------------------------------------------------------
[2017-01-05 21:46:05] kshah at fortinet dot com

I looked at the classification on https://wiki.php.net/security and I was unable to see how
this is "not" a security issue. 

Could you explain how it is not a security issue.

------------------------------------------------------------------------
[2017-01-05 21:28:31] stas@php.net

This definitely looks like infinite recursion, but if its buffer overflow may indicate some check
missing in recursion handling. Dmitry, could you take another look and see if there's not
anything we have missed?

In any case, not a security issue, please refer to https://wiki.php.net/security for classification.

------------------------------------------------------------------------
[2017-01-05 19:48:59] kshah at fortinet dot com

PHP Security Team, Any Update??

------------------------------------------------------------------------
[2016-12-20 17:16:00] kshah at fortinet dot com

Also as previously discussed with stas over email, the issue exists in latest php git build, php
released versions 7.0.12, 7.1 and maybe more on Linux platform.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=73755


--
Edit this bug report at https://bugs.php.net/bug.php?id=73755&edit=1


Thread (1 message)

  • stas@php.net
  • Unknown Message
    • stas@php.net
« previous php.bugs (#217851) next »