Bug #77177 [PATCH]: Serializing or unserializing COM objects crashes
| From: | 920768504@qq.com | Date: | Fri, 27 Nov 2020 02:32:58 +0000 |
| Subject: | Bug #77177 [PATCH]: Serializing or unserializing COM objects crashes | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-230660@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77177&edit=1
ID: 77177
Patch added by: 920768504@qq.com
Reported by: php at zsxsoft dot com
Summary: Serializing or unserializing COM objects crashes
Status: Closed
Type: Bug
Package: Reproducible crash
Operating System: Windows
PHP Version: PHP 7.1.24
Block user comment: N
Private report: N
New Comment:
The following patch has been added/updated:
Patch Name: patch
Revision: 1606444378
URL: https://bugs.php.net/patch-display.php?bug=77177&patch=patch&revision=1606444378
Previous Comments:
------------------------------------------------------------------------
[2020-01-18 16:30:45] dadaguo at 126 dot com
The following patch has been added/updated:
Patch Name: newtest0292
Revision: 1579365045
URL: https://bugs.php.net/patch-display.php?bug=77177&patch=newtest0292&revision=1579365045
------------------------------------------------------------------------
[2018-11-23 15:37:59] cmb@php.net
Automatic comment on behalf of cmbecker69@gmx.de
Revision: http://git.php.net/?p=php-src.git;a=commit;h=115ee49b0be12e3df7d2c7027609fbe1a1297e42
Log: Fix #77177: Serializing or unserializing COM objects crashes
------------------------------------------------------------------------
[2018-11-20 00:53:26] php at zsxsoft dot com
After fuzzing, I found
unserialize those classes can crash php:
- variant
- com
- dotnet
unserialize('O:7:"variant":0:{}');
unserialize('O:3:"com":0:{}');
unserialize('O:6:"dotnet":0:{}');
------------------------------------------------------------------------
[2018-11-20 00:40:33] php at zsxsoft dot com
Unserialize a com will cause a crash too.
------------------------------------------------------------------------
[2018-11-20 00:37:57] php at zsxsoft dot com
Also, unserialize a com will cause a crash too.
I reviewed the git blame and found this bug can effect from PHP 5.0RC1RC1 to branch master: https://github.com/php/php-src/blob/6df5d5ba202b531de6bb563e2462e046d701e8d6/ext/com_dotnet/com_handlers.c#L264.
Effected code
---------
ext/standard/var_unserializer.c
static inline int object_common2(UNSERIALIZE_PARAMETER, zend_long elements)
ht = Z_OBJPROP_P(rval);
if (elements >= (zend_long)(HT_MAX_SIZE - zend_hash_num_elements(ht))) {
return 0;
}
Code
---------
<?php
$c = unserialize('O:3:"com":0:{}');
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=77177
--
Edit this bug report at https://bugs.php.net/bug.php?id=77177&edit=1