Bug #77305 [Asn]: sigsev in __memcpy_sse2_unaligned due to sqlite bug
| From: | cmb@php.net | Date: | Mon, 24 Dec 2018 11:44:56 +0000 |
| Subject: | Bug #77305 [Asn]: sigsev in __memcpy_sse2_unaligned due to sqlite bug | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-218599@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77305&edit=1
ID: 77305
Updated by: cmb@php.net
Reported by: zero_420_ at yahoo dot com
Summary: sigsev in __memcpy_sse2_unaligned due to sqlite bug
Status: Assigned
Type: Bug
Package: SQLite related
Operating System: Ubuntu
PHP Version: 7.2.13
Assigned To: stas
Block user comment: N
Private report: N
New Comment:
> would you care to explain how it is not a security issue, if an
> attacker is already able to crash php within this context, it is
> not very hard for them to leverage this to bypass the security
> mechanisms such as disabled_functions.
If an attacker is able to crash PHP within this context, the
application is vulnerable to SQL injection, and this is the fault
of the application, not of PHP. If the application uses prepared
statements with bound variables only (which is recommended
anyway[1]), then it is not vulnerable to this kind of attack.
[1] <http://php.net/manual/en/security.database.sql-injection.php>
Previous Comments:
------------------------------------------------------------------------
[2018-12-24 01:53:35] zero_420_ at yahoo dot com
mitre has assigned CVE-2018-20346 to this issue in sqlite
------------------------------------------------------------------------
[2018-12-17 00:38:38] zero_420_ at yahoo dot com
adding on to the comment which @cmb referenced, https://news.ycombinator.com/item?id=18686572,
he further goes on to state
Correct. The primary error is that corrupt "shadow tables" used by the FTS3 full-text
search extension could cause RCE. The fix for that specific problem is here: https://www.sqlite.org/src/info/d44318f59044162e
------------------------------------------------------------------------
[2018-12-17 00:08:58] zero_420_ at yahoo dot com
would you care to explain how it is not a security issue, if an attacker is already able to crash
php within this context, it is not very hard for them to leverage this to bypass the security
mechanisms such as disabled_functions.
------------------------------------------------------------------------
[2018-12-16 22:59:30] stas@php.net
Looks like not a security issue then.
------------------------------------------------------------------------
[2018-12-16 22:54:56] cmb@php.net
Bohwaz just pointed out a related discussion on Hacker News where
the developer of SQLite3 states[1]:
| The vulnerability only exists in applications that allow a
| potential attacker to run arbitrary SQL.
While PHP allows developers to run arbitrary SQL, it also allows
to write to the database *file* directly which can be used to
corrupt it. Neither is supposed to be allowed for arbitrary
users, and developers are not supposed to shoot their own foot.
Therefore, in my opinion, this is not even a bug wrt. PHP, but
could be turned into a feature request, which could be satified by
something like Bohwaz's recent suggestion[2].
[1] <https://news.ycombinator.com/item?id=18686462>
[2] <https://github.com/php/php-src/pull/3709>
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=77305
--
Edit this bug report at https://bugs.php.net/bug.php?id=77305&edit=1