Bug #78833 [Ver->Csd]: Integer overflow in pack causes out-of-bound access
| From: | cmb@php.net | Date: | Mon, 02 Dec 2019 10:22:27 +0000 |
| Subject: | Bug #78833 [Ver->Csd]: Integer overflow in pack causes out-of-bound access | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-224002@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78833&edit=1
ID: 78833
Updated by: cmb@php.net
Reported by: thomas dot bouzerar at protonmail dot com
Summary: Integer overflow in pack causes out-of-bound access
-Status: Verified
+Status: Closed
Type: Bug
Package: Strings related
Operating System: ALL
PHP Version: 7.3.11
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of cmbecker69@gmx.de
Revision: http://git.php.net/?p=php-src.git;a=commit;h=db420cb6a141876b2f7d101051fb01934a28071a
Log: Fix #78833: Integer overflow in pack causes out-of-bound access
Previous Comments:
------------------------------------------------------------------------
[2019-11-19 13:23:42] cmb@php.net
The following pull request has been associated:
Patch Name: Fix #78833: Integer overflow in pack causes out-of-bound access
On GitHub: https://github.com/php/php-src/pull/4932
Patch: https://github.com/php/php-src/pull/4932.patch
------------------------------------------------------------------------
[2019-11-18 22:24:55] stas@php.net
Not a security issue, but probably worth adding a check.
------------------------------------------------------------------------
[2019-11-18 20:47:33] thomas dot bouzerar at protonmail dot com
Description:
------------
There exists an integer overflow in the builtin php function pack, as seen in the code below:
case 'E': /* big endian double */
if (arg < 0) {
arg = num_args - currentarg;
}
currentarg += arg; // currentarg (signed int) can be overflowed by chaining multiple positive
'arg' values
currentarg is later used by:
case 'H':
/* ... */
if (arg < 0) {
if (!try_convert_to_string(&argv[currentarg])) {
efree(formatcodes);
efree(formatargs);
return;
}
/* ... */
Causing an out-of-bounds read from argv array. This might lead to sensitive memory leak (although
not tested) or DoS.
Test script:
---------------
<?php
pack("E2E2147483647H*", 0x0, 0x0, 0x0);
?>
Expected result:
----------------
No segfault
Actual result:
--------------
Program received signal SIGSEGV, Segmentation fault.
0x000055555584c10e in ?? ()
$rax : 0x7ff7f521d100
$rbx : 0xf
$rcx : 0x48
$rdx : 0x2a
$rsp : 0x00007fffffffa510 â 0x0000000000000003
$rbp : 0x2
$rsi : 0x000055555584c208 â test eax, eax
$rdi : 0x00005555560a3190 â 0xff7a8f68ff5da44d
$rip : 0x000055555584c10e â cmp BYTE PTR [rax+0x8], 0x6
$r8 : 0x00007ffff5202ab8 â "E2E2147483647H*"
$r9 : 0x00005555560a2ee4 â 0xff7a8d1cff7a8d3c
$r10 : 0x00007ffff5277100 â 0x7fffffff00000002
$r11 : 0x00007ffff5202aa0 â 0x0000004600000001
$r12 : 0x48
$r13 : 0x00007ffff526a040 â 0x00007ffff5264545 â 0x0000000000000000
$r14 : 0xf
$r15 : 0x80000001
$eflags: [zero CARRY PARITY adjust sign trap INTERRUPT direction overflow RESUME virtualx86
identification]
$cs: 0x0033 $ss: 0x002b $ds: 0x0000 $es: 0x0000 $fs: 0x0000 $gs: 0x0000
âââââââââââââââââââââââââââââââââââââââââââââââââââââââ
code:x86:64 ââââ
0x55555584c102 movsxd rax, r15d
0x55555584c105 shl rax, 0x4
0x55555584c109 add rax, QWORD PTR [rsp+0x10]
â 0x55555584c10e cmp BYTE PTR [rax+0x8], 0x6
0x55555584c112 je 0x55555584c14c
0x55555584c114 mov QWORD PTR [rsp+0x28], r10
0x55555584c119 mov rdi, rax
0x55555584c11c mov QWORD PTR [rsp+0x20], r8
0x55555584c121 mov QWORD PTR [rsp+0x18], r11
âââââââââââââââââââââââââââââââââââââââââââââââââââââââââââ
threads ââââ
[#0] Id 1, Name: "php", stopped, reason: SIGSEGV
âââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââ
trace ââââ
[#0] 0x55555584c10e â cmp BYTE PTR [rax+0x8], 0x6
[#1] 0x555555993048 â execute_ex()
[#2] 0x555555997d46 â zend_execute()
[#3] 0x5555559105eb â zend_execute_scripts()
[#4] 0x5555558b2cf9 â php_execute_script()
[#5] 0x55555599a33d â lea rax, [rip+0x8951fc] # 0x55555622f540 <executor_globals>
[#6] 0x5555556a1fa7 â mov ebp, eax
[#7] 0x7ffff74ab153 â __libc_start_main()
[#8] 0x5555556a26ce â _start()
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=78833&edit=1