Bug #62474 [Ver->Csd]: com_event_sink crashes when closure object given as an argument

From: Date: Mon, 26 Oct 2020 10:56:41 +0000
Subject: Bug #62474 [Ver->Csd]: com_event_sink crashes when closure object given as an argument
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-229925@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=62474&edit=1

 ID:                 62474
 Updated by:         cmb@php.net
 Reported by:        deadb17ch at gmail dot com
 Summary:            com_event_sink crashes when closure object given as
                     an argument
-Status:             Verified
+Status:             Closed
 Type:               Bug
 Package:            COM related
 Operating System:   Windows XP SP3
 PHP Version:        7.3
 Assigned To:        cmb
 Block user comment: N
 Private report:     N

 New Comment:

Automatic comment on behalf of cmbecker69@gmx.de
Revision: http://git.php.net/?p=php-src.git;a=commit;h=7424bfc7ac772687a681e42081ea0d8943f0d85e
Log: Fix #62474: com_event_sink crashes on certain arguments


Previous Comments:
------------------------------------------------------------------------
[2020-10-23 11:45:58] cmb@php.net

The following pull request has been associated:

Patch Name: Fix #62474: com_event_sink crashes on certain arguments
On GitHub:  https://github.com/php/php-src/pull/6372
Patch:      https://github.com/php/php-src/pull/6372.patch

------------------------------------------------------------------------
[2020-10-22 16:12:17] cmb@php.net

Unlikely to be remotely exploitable, but still a bug.

------------------------------------------------------------------------
[2012-09-11 14:08:58] fb1h2s at gmail dot com

A reliable way to get coded execution  http://www.garage4hackers.com/blogs/8/web-
app-remote-code-execution-via-scripting-engines-part-1-local-exploits-php-0-day-
394/ using this bug.

------------------------------------------------------------------------
[2012-07-27 20:43:06] fb1h2s at gmail dot com

Oh yea my mistake I was referring to arg 1 crash, dint see a Bug Id open for that here though.

<?php


$buffer = str_repeat("A", 1000);


$vVar = new VARIANT(0x41414141); // We controll this
$vVar2 = new VARIANT(0x41414141); // 


com_event_sink($vVar, $vVar2 , $buffer );

?>

------------------------------------------------------------------------
[2012-07-26 13:43:04] deadb17ch at gmail dot com

I know. I have send an advisory about possible code execution  in com_event_sink()  
function using VARIANT object to bugtraq some time ago (21 May) :

http://cxsecurity.com/issue/WLB-2012050163
http://www.exploit-db.com/exploits/18910/

but this time it is about bug in second argument, not first.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=62474


--
Edit this bug report at https://bugs.php.net/bug.php?id=62474&edit=1


Thread (8 messages)

« previous php.bugs (#229925) next »