Bug #77305 [Asn->Csd]: sigsev in __memcpy_sse2_unaligned due to sqlite bug
| From: | cmb@php.net | Date: | Tue, 09 Jul 2019 09:18:01 +0000 |
| Subject: | Bug #77305 [Asn->Csd]: sigsev in __memcpy_sse2_unaligned due to sqlite bug | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-221668@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77305&edit=1
ID: 77305
Updated by: cmb@php.net
Reported by: zero_420_ at yahoo dot com
Summary: sigsev in __memcpy_sse2_unaligned due to sqlite bug
-Status: Assigned
+Status: Closed
Type: Bug
Package: SQLite related
Operating System: Ubuntu
PHP Version: 7.2.13
-Assigned To: stas
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
The bundled libsqlite has now been updated to 3.28.0 for all
supported branches (including PHP-7.1), so this ticket can be
closed.
Previous Comments:
------------------------------------------------------------------------
[2019-01-29 16:16:43] cmb@php.net
Related To: Bug #77541
------------------------------------------------------------------------
[2018-12-25 11:54:57] spam2 at rhsoft dot net
you can have your arbitrary definitions as you like, for the rest of the world bugs which lead to
denial of service are security bugs
for shared hosting it is critical when random php code leads to segfaults of the whole service and
fpm pools just mask the issue
------------------------------------------------------------------------
[2018-12-25 11:35:54] cmb@php.net
We are assessing security related bug reports according to our
security classification document[1]. This report falls in the
âNot a security issueâ category[2], since it
| requires the use of code or settings known to be insecure
which is certainly the case for arbitrary SQL injection.
This security classification document has been agreed upon via a
respective RFC[3]. If you think the security classification is
flawed, please bring that up on internals@php.net, since this bug
tracker is unsuitable for such discussions. Thanks!
[1] <https://wiki.php.net/security>
[2] <https://wiki.php.net/security#not_a_security_issue>
[3] <https://wiki.php.net/rfc/security-classification>
------------------------------------------------------------------------
[2018-12-24 23:49:17] zero_420_ at yahoo dot com
just as @spam2 has stated this is true, and it appears that @cmb is oblivious to the fact that this
is far more dangerous than simple sql injection because it can be leveraged by an attacker to
execute code on the box locally bypassing security measures like disabled functions, however, as we
typically see on most of these reports from the php devs, its almost as if their job titles are
downplay anything with a security impact, or just ignore the reports flat out
------------------------------------------------------------------------
[2018-12-24 11:47:54] spam2 at rhsoft dot net
there is still a difference between vulerable to sql-injection and be able to crash the service
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=77305
--
Edit this bug report at https://bugs.php.net/bug.php?id=77305&edit=1