Bug #79078 [NEW]: Hypothetical use-after-free in curl_multi_add_handle()
| From: | cmb@php.net | Date: | Wed, 08 Jan 2020 10:48:46 +0000 |
| Subject: | Bug #79078 [NEW]: Hypothetical use-after-free in curl_multi_add_handle() | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-224770@lists.php.net to get a copy of this message | ||
From: cmb
Operating system: *
PHP version: 7.3Git-2020-01-08 (Git)
Package: cURL related
Bug Type: Bug
Bug description:Hypothetical use-after-free in curl_multi_add_handle()
Description:
------------
If a curl resource which has CURLOPT_VERBOSE enabled, and
CURLOPT_STDERR set to a stream which has been prematurely closed
is passed to curl_multi_add_handle(), depending on the libcurl
version, there may be an use-after-free.
Since this requires debugging features (CURLOPT_VERBOSE) and a
rather serious programming error, this is not a security bug.
Test script:
---------------
php -i | grep cURL
php run-tests.php -m ext/curl/tests/bug48203_multi.phpt > /dev/null
2>&1
cat ext/curl/tests/bug48203_multi.mem
Expected result:
----------------
cURL support => enabled
cURL Information => 7.64.0
cat: ext/curl/bug48203_multi.mem: No such file or directory
Actual result:
--------------
cURL support => enabled
cURL Information => 7.64.0
==30168== Invalid read of size 4
==30168== at 0x6C0CF6E: fwrite (iofwrite.c:37)
==30168== by 0x5BC806C: Curl_debug (in
/home/cmb/curl/lib/libcurl.so.4.5.0)
==30168== by 0x5BC81E5: Curl_infof (in
/home/cmb/curl/lib/libcurl.so.4.5.0)
==30168== by 0x5BE04A1: Curl_expire (in
/home/cmb/curl/lib/libcurl.so.4.5.0)
==30168== by 0x5BE07A9: curl_multi_add_handle (in
/home/cmb/curl/lib/libcurl.so.4.5.0)
==30168== by 0x2812B5: zif_curl_multi_add_handle (multi.c:100)
==30168== by 0x426867: ZEND_DO_ICALL_SPEC_RETVAL_UNUSED_HANDLER
(zend_vm_execute.h:649)
==30168== by 0x426867: execute_ex (zend_vm_execute.h:55503)
==30168== by 0x42EFBF: zend_execute (zend_vm_execute.h:60939)
==30168== by 0x3A529A: zend_execute_scripts (zend.c:1568)
==30168== by 0x344E1F: php_execute_script (main.c:2639)
==30168== by 0x43130D: do_cli (php_cli.c:997)
==30168== by 0x1E74CC: main (php_cli.c:1389)
==30168== Address 0x7990500 is 0 bytes inside a block of size 552
free'd
==30168== at 0x4C2CDDB: free (vg_replace_malloc.c:530)
==30168== by 0x6C0BC41: fclose@@GLIBC_2.2.5 (iofclose.c:84)
==30168== by 0x362197: php_stdiop_close (plain_wrapper.c:464)
==30168== by 0x35D277: _php_stream_free (streams.c:466)
==30168== by 0x2E74B0: zif_fclose (file.c:920)
==30168== by 0x426867: ZEND_DO_ICALL_SPEC_RETVAL_UNUSED_HANDLER
(zend_vm_execute.h:649)
==30168== by 0x426867: execute_ex (zend_vm_execute.h:55503)
==30168== by 0x42EFBF: zend_execute (zend_vm_execute.h:60939)
==30168== by 0x3A529A: zend_execute_scripts (zend.c:1568)
==30168== by 0x344E1F: php_execute_script (main.c:2639)
==30168== by 0x43130D: do_cli (php_cli.c:997)
==30168== by 0x1E74CC: main (php_cli.c:1389)
==30168== Block was alloc'd at
==30168== at 0x4C2BBAF: malloc (vg_replace_malloc.c:299)
==30168== by 0x6C0BE52: fdopen@@GLIBC_2.2.5 (iofdopen.c:139)
==30168== by 0x362077: php_stdiop_cast (plain_wrapper.c:559)
==30168== by 0x35FB0F: _php_stream_cast (cast.c:220)
==30168== by 0x27C9E0: _php_curl_setopt (interface.c:2562)
==30168== by 0x27E04F: zif_curl_setopt_array (interface.c:3125)
==30168== by 0x42CDEC:
ZEND_DO_FCALL_BY_NAME_SPEC_RETVAL_UNUSED_HANDLER
(zend_vm_execute.h:819)
==30168== by 0x42CDEC: execute_ex (zend_vm_execute.h:55519)
==30168== by 0x42EFBF: zend_execute (zend_vm_execute.h:60939)
==30168== by 0x3A529A: zend_execute_scripts (zend.c:1568)
==30168== by 0x344E1F: php_execute_script (main.c:2639)
==30168== by 0x43130D: do_cli (php_cli.c:997)
==30168== by 0x1E74CC: main (php_cli.c:1389)
<snip>
--
Edit bug report at https://bugs.php.net/bug.php?id=79078&edit=1
--
Fix committed: https://bugs.php.net/fix.php?id=79078&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=79078&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=79078&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=79078&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=79078&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=79078&r=support
Expected behavior: https://bugs.php.net/fix.php?id=79078&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=79078&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=79078&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=79078&r=globals
PHP version support discontinued: https://bugs.php.net/fix.php?id=79078&r=phptooold
Daylight Savings: https://bugs.php.net/fix.php?id=79078&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=79078&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=79078&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=79078&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=79078&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=79078&r=mysqlcfg