Bug #62474 [PATCH]: com_event_sink crashes when closure object given as an argument
Edit report at https://bugs.php.net/bug.php?id=62474&edit=1
ID: 62474
Patch added by: cmb@php.net
Reported by: deadb17ch at gmail dot com
Summary: com_event_sink crashes when closure object given as
an argument
Status: Verified
Type: Bug
Package: COM related
Operating System: Windows XP SP3
PHP Version: 7.3
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
The following pull request has been associated:
Patch Name: Fix #62474: com_event_sink crashes on certain arguments
On GitHub: https://github.com/php/php-src/pull/6372
Patch: https://github.com/php/php-src/pull/6372.patch
Previous Comments:
------------------------------------------------------------------------
[2020-10-22 16:12:17] cmb@php.net
Unlikely to be remotely exploitable, but still a bug.
------------------------------------------------------------------------
[2012-09-11 14:08:58] fb1h2s at gmail dot com
A reliable way to get coded execution http://www.garage4hackers.com/blogs/8/web-
app-remote-code-execution-via-scripting-engines-part-1-local-exploits-php-0-day-
394/ using this bug.
------------------------------------------------------------------------
[2012-07-27 20:43:06] fb1h2s at gmail dot com
Oh yea my mistake I was referring to arg 1 crash, dint see a Bug Id open for that here though.
<?php
$buffer = str_repeat("A", 1000);
$vVar = new VARIANT(0x41414141); // We controll this
$vVar2 = new VARIANT(0x41414141); //
com_event_sink($vVar, $vVar2 , $buffer );
?>
------------------------------------------------------------------------
[2012-07-26 13:43:04] deadb17ch at gmail dot com
I know. I have send an advisory about possible code execution in com_event_sink()
function using VARIANT object to bugtraq some time ago (21 May) :
http://cxsecurity.com/issue/WLB-2012050163
http://www.exploit-db.com/exploits/18910/
but this time it is about bug in second argument, not first.
------------------------------------------------------------------------
[2012-07-26 13:32:17] fb1h2s at gmail dot com
It's possible to achieve code execution using this bug.
$_evil_object = new VARIANT(0x41414141);
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=62474
--
Edit this bug report at https://bugs.php.net/bug.php?id=62474&edit=1
Thread (8 messages)