Sec Bug->Bug #77305 [Asn]: sigsev in __memcpy_sse2_unaligned due to sqlite bug
| From: | stas@php.net | Date: | Sun, 16 Dec 2018 22:59:30 +0000 |
| Subject: | Sec Bug->Bug #77305 [Asn]: sigsev in __memcpy_sse2_unaligned due to sqlite bug | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-218472@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77305&edit=1
ID: 77305
Updated by: stas@php.net
Reported by: zero_420_ at yahoo dot com
Summary: sigsev in __memcpy_sse2_unaligned due to sqlite bug
Status: Assigned
-Type: Security
+Type: Bug
Package: SQLite related
Operating System: Ubuntu
-PHP Version: 5.6.39
+PHP Version: 7.2.13
Assigned To: stas
Block user comment: N
Private report: Y
New Comment:
Looks like not a security issue then.
Previous Comments:
------------------------------------------------------------------------
[2018-12-16 22:54:56] cmb@php.net
Bohwaz just pointed out a related discussion on Hacker News where
the developer of SQLite3 states[1]:
| The vulnerability only exists in applications that allow a
| potential attacker to run arbitrary SQL.
While PHP allows developers to run arbitrary SQL, it also allows
to write to the database *file* directly which can be used to
corrupt it. Neither is supposed to be allowed for arbitrary
users, and developers are not supposed to shoot their own foot.
Therefore, in my opinion, this is not even a bug wrt. PHP, but
could be turned into a feature request, which could be satified by
something like Bohwaz's recent suggestion[2].
[1] <https://news.ycombinator.com/item?id=18686462>
[2] <https://github.com/php/php-src/pull/3709>
------------------------------------------------------------------------
[2018-12-16 16:38:26] zero_420_ at yahoo dot com
the chromium bug report is https://crbug.com/900910 however
it is private, but the changelog located here
https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html
states
[$TBD][900910] High To be allocated: Multiple issues in SQLite via WebSQL. Reported by Wenxiang Qian
of Tencent Blade Team on 2018-11-01
so it does appear that there are cve's pending for this
------------------------------------------------------------------------
[2018-12-16 12:11:27] cmb@php.net
Sorry, my question was misleadingly worded. Of course, we should
not have an own CVE-ID, but rather re-use the one assinged to SQLite3.
However, SQLite3 already shipped the commit you've mentioned, and
the release notes[1] state:
| Strengthen defenses against deliberately corrupted database files.
*Deliberately* corrupted database files would not be a security
issue according to our classification[2], though. Also, the
respective chromium fix[3] doesn't mention anything security
related.
[1] <https://sqlite.org/releaselog/3_25_3.html>
[2] <https://wiki.php.net/security>
[3] <https://chromium.googlesource.com/chromium/src/+/c368e30ae55600a1c3c9cb1710a54f9c55de786e>
------------------------------------------------------------------------
[2018-12-16 01:44:25] zero_420_ at yahoo dot com
i have not submitted a cve request regarding php being affected by this, however i believe there are
cve's pending request regarding the sqlite issues as reported by Wenxiang Qian of the tenecent
blade team.
if you feel that the impact of this warrants a cve then i can submit a request for one if need be
------------------------------------------------------------------------
[2018-12-16 01:27:47] stas@php.net
Should be updated in 5.6 too probably,
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=77305
--
Edit this bug report at https://bugs.php.net/bug.php?id=77305&edit=1