Bug #77305 [Asn]: sigsev in __memcpy_sse2_unaligned due to sqlite bug

From: Date: Mon, 24 Dec 2018 23:49:17 +0000
Subject: Bug #77305 [Asn]: sigsev in __memcpy_sse2_unaligned due to sqlite bug
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-218605@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77305&edit=1 ID: 77305 User updated by: zero_420_ at yahoo dot com Reported by: zero_420_ at yahoo dot com Summary: sigsev in __memcpy_sse2_unaligned due to sqlite bug Status: Assigned Type: Bug Package: SQLite related Operating System: Ubuntu PHP Version: 7.2.13 Assigned To: stas Block user comment: N Private report: N New Comment: just as @spam2 has stated this is true, and it appears that @cmb is oblivious to the fact that this is far more dangerous than simple sql injection because it can be leveraged by an attacker to execute code on the box locally bypassing security measures like disabled functions, however, as we typically see on most of these reports from the php devs, its almost as if their job titles are downplay anything with a security impact, or just ignore the reports flat out Previous Comments: ------------------------------------------------------------------------ [2018-12-24 11:47:54] spam2 at rhsoft dot net there is still a difference between vulerable to sql-injection and be able to crash the service ------------------------------------------------------------------------ [2018-12-24 11:44:56] cmb@php.net > would you care to explain how it is not a security issue, if an > attacker is already able to crash php within this context, it is > not very hard for them to leverage this to bypass the security > mechanisms such as disabled_functions. If an attacker is able to crash PHP within this context, the application is vulnerable to SQL injection, and this is the fault of the application, not of PHP. If the application uses prepared statements with bound variables only (which is recommended anyway[1]), then it is not vulnerable to this kind of attack. [1] <http://php.net/manual/en/security.database.sql-injection.php> ------------------------------------------------------------------------ [2018-12-24 01:53:35] zero_420_ at yahoo dot com mitre has assigned CVE-2018-20346 to this issue in sqlite ------------------------------------------------------------------------ [2018-12-17 00:38:38] zero_420_ at yahoo dot com adding on to the comment which @cmb referenced, https://news.ycombinator.com/item?id=18686572, he further goes on to state Correct. The primary error is that corrupt "shadow tables" used by the FTS3 full-text search extension could cause RCE. The fix for that specific problem is here: https://www.sqlite.org/src/info/d44318f59044162e ------------------------------------------------------------------------ [2018-12-17 00:08:58] zero_420_ at yahoo dot com would you care to explain how it is not a security issue, if an attacker is already able to crash php within this context, it is not very hard for them to leverage this to bypass the security mechanisms such as disabled_functions. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=77305 -- Edit this bug report at https://bugs.php.net/bug.php?id=77305&edit=1

« previous php.bugs (#218605) next »