Bug #62474 [Ver->Csd]: com_event_sink crashes when closure object given as an argument
Edit report at https://bugs.php.net/bug.php?id=62474&edit=1
ID: 62474
Updated by: cmb@php.net
Reported by: deadb17ch at gmail dot com
Summary: com_event_sink crashes when closure object given as
an argument
-Status: Verified
+Status: Closed
Type: Bug
Package: COM related
Operating System: Windows XP SP3
PHP Version: 7.3
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of cmbecker69@gmx.de
Revision: http://git.php.net/?p=php-src.git;a=commit;h=7424bfc7ac772687a681e42081ea0d8943f0d85e
Log: Fix #62474: com_event_sink crashes on certain arguments
Previous Comments:
------------------------------------------------------------------------
[2020-10-23 11:45:58] cmb@php.net
The following pull request has been associated:
Patch Name: Fix #62474: com_event_sink crashes on certain arguments
On GitHub: https://github.com/php/php-src/pull/6372
Patch: https://github.com/php/php-src/pull/6372.patch
------------------------------------------------------------------------
[2020-10-22 16:12:17] cmb@php.net
Unlikely to be remotely exploitable, but still a bug.
------------------------------------------------------------------------
[2012-09-11 14:08:58] fb1h2s at gmail dot com
A reliable way to get coded execution http://www.garage4hackers.com/blogs/8/web-
app-remote-code-execution-via-scripting-engines-part-1-local-exploits-php-0-day-
394/ using this bug.
------------------------------------------------------------------------
[2012-07-27 20:43:06] fb1h2s at gmail dot com
Oh yea my mistake I was referring to arg 1 crash, dint see a Bug Id open for that here though.
<?php
$buffer = str_repeat("A", 1000);
$vVar = new VARIANT(0x41414141); // We controll this
$vVar2 = new VARIANT(0x41414141); //
com_event_sink($vVar, $vVar2 , $buffer );
?>
------------------------------------------------------------------------
[2012-07-26 13:43:04] deadb17ch at gmail dot com
I know. I have send an advisory about possible code execution in com_event_sink()
function using VARIANT object to bugtraq some time ago (21 May) :
http://cxsecurity.com/issue/WLB-2012050163
http://www.exploit-db.com/exploits/18910/
but this time it is about bug in second argument, not first.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=62474
--
Edit this bug report at https://bugs.php.net/bug.php?id=62474&edit=1
Thread (8 messages)