Bug #80111 [Opn->Csd]: PHP SplDoublyLinkedList::offsetUnset UAF Sandbox Escape
| From: | git@php.net | Date: | Mon, 19 Apr 2021 12:42:10 +0000 |
| Subject: | Bug #80111 [Opn->Csd]: PHP SplDoublyLinkedList::offsetUnset UAF Sandbox Escape | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-233505@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=80111&edit=1
ID: 80111
Updated by: git@php.net
Reported by: noamr at ssd-disclosure dot com
Summary: PHP SplDoublyLinkedList::offsetUnset UAF Sandbox
Escape
-Status: Open
+Status: Closed
Type: Bug
Package: *General Issues
Operating System: Debian / Buster
PHP Version: 7.4.10
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of nikic
Revision: https://github.com/php/php-src/commit/71cbef78badfffe6dbd944270e84bece024225f4
Log: Fixed bug #80111
Previous Comments:
------------------------------------------------------------------------
[2020-09-24 08:43:07] noamr at ssd-disclosure dot com
Hi,
Ok
We will publish this information
------------------------------------------------------------------------
[2020-09-17 11:07:10] cmb@php.net
According to our security classification, this is not a security
issue[1], because it requires very special exploit code on the
server. If an attacker is able to inject code, there may be more
serious issues than bypassing disable_functions (note that
safe_mode is gone for many years).
[1] <https://wiki.php.net/security#not_a_security_issue>
------------------------------------------------------------------------
[2020-09-17 09:56:41] noamr at ssd-disclosure dot com
Security
------------------------------------------------------------------------
[2020-09-17 09:56:16] noamr at ssd-disclosure dot com
This is a security vulnerability - shouldn't be open
------------------------------------------------------------------------
[2020-09-17 09:55:36] noamr at ssd-disclosure dot com
Hi,
We also have a working exploit if you require one
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=80111
--
Edit this bug report at https://bugs.php.net/bug.php?id=80111&edit=1