Sec Bug->Bug #77494 [Opn]: Disabling class causes segfault on member access

From: Date: Mon, 21 Jan 2019 01:14:44 +0000
Subject: Sec Bug->Bug #77494 [Opn]: Disabling class causes segfault on member access
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-219099@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77494&edit=1

 ID:                 77494
 Updated by:         stas@php.net
 Reported by:        64796c6e69 at gmail dot com
-Summary:            Disabling CURLFile does not work
+Summary:            Disabling class causes segfault on member access
 Status:             Open
-Type:               Security
+Type:               Bug
-Package:            cURL related
+Package:            Scripting Engine problem
 Operating System:   Linux
 PHP Version:        7.3Git-2019-01-20 (Git)
-Assigned To:        
+Assigned To:        dmitry
 Block user comment: N
 Private report:     Y

 New Comment:

Looks like the problem happens because disabled class ctor is not calling object_properties_init,
thus properties remain un-initialized when disabling the class and access to them results in
accessing uninitialized data. 
Not sure why cli and CGI differ here - may be how memory allocator works there? Or maybe some switch
I've missed?
Doesn't seem to be security issue since requires special user-side code. 

I am not super-familiar with new object code though so I think somebody like Nikita or Dmitry should
take a look and see if my diagnosis is correct.


Previous Comments:
------------------------------------------------------------------------
[2019-01-20 23:00:17] 64796c6e69 at gmail dot com

Description:
------------
When CURLFile is disabled using disable_classes, curl_file_create() and new CURLFile() only give
warnings. The class is still constructed even when strict types are enabled.

Worse, if the object was constructed with no arguments using either method, working with it further
causes a segfault when the class is disabled. The segfault happens in interactive mode and CGI. I
also tested CLI, which does not have the problem.

Another strange problem is that some longer filenames do not cause a segfault. For example, name the
file file123456789.php, and the var_dump() line outputs NULL.

All of the described behavior happens in PHP 7.2 and the master branch from Git.

Test script:
---------------
CLI:
php-cgi -ddisable_classes=CURLFile -ffile.php

file.php:
<?php
$a = new CURLFile();
var_dump($a->name);

Expected result:
----------------
An error about the class being disabled.

Actual result:
--------------
<br />
<b>Warning</b>:  CURLFile() has been disabled for security reasons in
<b>REDACTED/file.php</b> on line <b>2</b><br />
UNKNOWN:0
Segmentation fault (core dumped)


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=77494&edit=1


Thread (1 message)

  • stas@php.net
  • Unknown Message
    • stas@php.net
« previous php.bugs (#219099) next »