Bug #62474 [PATCH]: com_event_sink crashes when closure object given as an argument

From: Date: Fri, 23 Oct 2020 11:45:58 +0000
Subject: Bug #62474 [PATCH]: com_event_sink crashes when closure object given as an argument
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-229865@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=62474&edit=1

 ID:                 62474
 Patch added by:     cmb@php.net
 Reported by:        deadb17ch at gmail dot com
 Summary:            com_event_sink crashes when closure object given as
                     an argument
 Status:             Verified
 Type:               Bug
 Package:            COM related
 Operating System:   Windows XP SP3
 PHP Version:        7.3
 Assigned To:        cmb
 Block user comment: N
 Private report:     N

 New Comment:

The following pull request has been associated:

Patch Name: Fix #62474: com_event_sink crashes on certain arguments
On GitHub:  https://github.com/php/php-src/pull/6372
Patch:      https://github.com/php/php-src/pull/6372.patch


Previous Comments:
------------------------------------------------------------------------
[2020-10-22 16:12:17] cmb@php.net

Unlikely to be remotely exploitable, but still a bug.

------------------------------------------------------------------------
[2012-09-11 14:08:58] fb1h2s at gmail dot com

A reliable way to get coded execution  http://www.garage4hackers.com/blogs/8/web-
app-remote-code-execution-via-scripting-engines-part-1-local-exploits-php-0-day-
394/ using this bug.

------------------------------------------------------------------------
[2012-07-27 20:43:06] fb1h2s at gmail dot com

Oh yea my mistake I was referring to arg 1 crash, dint see a Bug Id open for that here though.

<?php


$buffer = str_repeat("A", 1000);


$vVar = new VARIANT(0x41414141); // We controll this
$vVar2 = new VARIANT(0x41414141); // 


com_event_sink($vVar, $vVar2 , $buffer );

?>

------------------------------------------------------------------------
[2012-07-26 13:43:04] deadb17ch at gmail dot com

I know. I have send an advisory about possible code execution  in com_event_sink()  
function using VARIANT object to bugtraq some time ago (21 May) :

http://cxsecurity.com/issue/WLB-2012050163
http://www.exploit-db.com/exploits/18910/

but this time it is about bug in second argument, not first.

------------------------------------------------------------------------
[2012-07-26 13:32:17] fb1h2s at gmail dot com

It's possible to achieve code execution using this bug. 

$_evil_object = new VARIANT(0x41414141);

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=62474


--
Edit this bug report at https://bugs.php.net/bug.php?id=62474&edit=1


Thread (8 messages)

« previous php.bugs (#229865) next »