Bug #80111 [Opn->Csd]: PHP SplDoublyLinkedList::offsetUnset UAF Sandbox Escape

From: Date: Mon, 19 Apr 2021 12:42:10 +0000
Subject: Bug #80111 [Opn->Csd]: PHP SplDoublyLinkedList::offsetUnset UAF Sandbox Escape
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-233505@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80111&edit=1 ID: 80111 Updated by: git@php.net Reported by: noamr at ssd-disclosure dot com Summary: PHP SplDoublyLinkedList::offsetUnset UAF Sandbox Escape -Status: Open +Status: Closed Type: Bug Package: *General Issues Operating System: Debian / Buster PHP Version: 7.4.10 Block user comment: N Private report: N New Comment: Automatic comment on behalf of nikic Revision: https://github.com/php/php-src/commit/71cbef78badfffe6dbd944270e84bece024225f4 Log: Fixed bug #80111 Previous Comments: ------------------------------------------------------------------------ [2020-09-24 08:43:07] noamr at ssd-disclosure dot com Hi, Ok We will publish this information ------------------------------------------------------------------------ [2020-09-17 11:07:10] cmb@php.net According to our security classification, this is not a security issue[1], because it requires very special exploit code on the server. If an attacker is able to inject code, there may be more serious issues than bypassing disable_functions (note that safe_mode is gone for many years). [1] <https://wiki.php.net/security#not_a_security_issue> ------------------------------------------------------------------------ [2020-09-17 09:56:41] noamr at ssd-disclosure dot com Security ------------------------------------------------------------------------ [2020-09-17 09:56:16] noamr at ssd-disclosure dot com This is a security vulnerability - shouldn't be open ------------------------------------------------------------------------ [2020-09-17 09:55:36] noamr at ssd-disclosure dot com Hi, We also have a working exploit if you require one ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=80111 -- Edit this bug report at https://bugs.php.net/bug.php?id=80111&edit=1

« previous php.bugs (#233505) next »