Bug #77177 [PATCH]: Serializing or unserializing COM objects crashes

From: Date: Fri, 27 Nov 2020 02:32:58 +0000
Subject: Bug #77177 [PATCH]: Serializing or unserializing COM objects crashes
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-230660@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77177&edit=1 ID: 77177 Patch added by: 920768504@qq.com Reported by: php at zsxsoft dot com Summary: Serializing or unserializing COM objects crashes Status: Closed Type: Bug Package: Reproducible crash Operating System: Windows PHP Version: PHP 7.1.24 Block user comment: N Private report: N New Comment: The following patch has been added/updated: Patch Name: patch Revision: 1606444378 URL: https://bugs.php.net/patch-display.php?bug=77177&patch=patch&revision=1606444378 Previous Comments: ------------------------------------------------------------------------ [2020-01-18 16:30:45] dadaguo at 126 dot com The following patch has been added/updated: Patch Name: newtest0292 Revision: 1579365045 URL: https://bugs.php.net/patch-display.php?bug=77177&patch=newtest0292&revision=1579365045 ------------------------------------------------------------------------ [2018-11-23 15:37:59] cmb@php.net Automatic comment on behalf of cmbecker69@gmx.de Revision: http://git.php.net/?p=php-src.git;a=commit;h=115ee49b0be12e3df7d2c7027609fbe1a1297e42 Log: Fix #77177: Serializing or unserializing COM objects crashes ------------------------------------------------------------------------ [2018-11-20 00:53:26] php at zsxsoft dot com After fuzzing, I found unserialize those classes can crash php: - variant - com - dotnet unserialize('O:7:"variant":0:{}'); unserialize('O:3:"com":0:{}'); unserialize('O:6:"dotnet":0:{}'); ------------------------------------------------------------------------ [2018-11-20 00:40:33] php at zsxsoft dot com Unserialize a com will cause a crash too. ------------------------------------------------------------------------ [2018-11-20 00:37:57] php at zsxsoft dot com Also, unserialize a com will cause a crash too. I reviewed the git blame and found this bug can effect from PHP 5.0RC1RC1 to branch master: https://github.com/php/php-src/blob/6df5d5ba202b531de6bb563e2462e046d701e8d6/ext/com_dotnet/com_handlers.c#L264. Effected code --------- ext/standard/var_unserializer.c static inline int object_common2(UNSERIALIZE_PARAMETER, zend_long elements) ht = Z_OBJPROP_P(rval); if (elements >= (zend_long)(HT_MAX_SIZE - zend_hash_num_elements(ht))) { return 0; } Code --------- <?php $c = unserialize('O:3:"com":0:{}'); ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=77177 -- Edit this bug report at https://bugs.php.net/bug.php?id=77177&edit=1

« previous php.bugs (#230660) next »