Bug #77305 [Com]: sigsev in __memcpy_sse2_unaligned due to sqlite bug

From: Date: Mon, 17 Dec 2018 00:38:38 +0000
Subject: Bug #77305 [Com]: sigsev in __memcpy_sse2_unaligned due to sqlite bug
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-218474@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77305&edit=1 ID: 77305 Comment by: zero_420_ at yahoo dot com Reported by: zero_420_ at yahoo dot com Summary: sigsev in __memcpy_sse2_unaligned due to sqlite bug Status: Assigned Type: Bug Package: SQLite related Operating System: Ubuntu PHP Version: 7.2.13 Assigned To: stas Block user comment: N Private report: N New Comment: adding on to the comment which @cmb referenced, https://news.ycombinator.com/item?id=18686572, he further goes on to state Correct. The primary error is that corrupt "shadow tables" used by the FTS3 full-text search extension could cause RCE. The fix for that specific problem is here: https://www.sqlite.org/src/info/d44318f59044162e Previous Comments: ------------------------------------------------------------------------ [2018-12-17 00:08:58] zero_420_ at yahoo dot com would you care to explain how it is not a security issue, if an attacker is already able to crash php within this context, it is not very hard for them to leverage this to bypass the security mechanisms such as disabled_functions. ------------------------------------------------------------------------ [2018-12-16 22:59:30] stas@php.net Looks like not a security issue then. ------------------------------------------------------------------------ [2018-12-16 22:54:56] cmb@php.net Bohwaz just pointed out a related discussion on Hacker News where the developer of SQLite3 states[1]: | The vulnerability only exists in applications that allow a | potential attacker to run arbitrary SQL. While PHP allows developers to run arbitrary SQL, it also allows to write to the database *file* directly which can be used to corrupt it. Neither is supposed to be allowed for arbitrary users, and developers are not supposed to shoot their own foot. Therefore, in my opinion, this is not even a bug wrt. PHP, but could be turned into a feature request, which could be satified by something like Bohwaz's recent suggestion[2]. [1] <https://news.ycombinator.com/item?id=18686462> [2] <https://github.com/php/php-src/pull/3709> ------------------------------------------------------------------------ [2018-12-16 16:38:26] zero_420_ at yahoo dot com the chromium bug report is https://crbug.com/900910 however it is private, but the changelog located here https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html states [$TBD][900910] High To be allocated: Multiple issues in SQLite via WebSQL. Reported by Wenxiang Qian of Tencent Blade Team on 2018-11-01 so it does appear that there are cve's pending for this ------------------------------------------------------------------------ [2018-12-16 12:11:27] cmb@php.net Sorry, my question was misleadingly worded. Of course, we should not have an own CVE-ID, but rather re-use the one assinged to SQLite3. However, SQLite3 already shipped the commit you've mentioned, and the release notes[1] state: | Strengthen defenses against deliberately corrupted database files. *Deliberately* corrupted database files would not be a security issue according to our classification[2], though. Also, the respective chromium fix[3] doesn't mention anything security related. [1] <https://sqlite.org/releaselog/3_25_3.html> [2] <https://wiki.php.net/security> [3] <https://chromium.googlesource.com/chromium/src/+/c368e30ae55600a1c3c9cb1710a54f9c55de786e> ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=77305 -- Edit this bug report at https://bugs.php.net/bug.php?id=77305&edit=1

« previous php.bugs (#218474) next »