Sec Bug->Bug #73246 [Asn]: Stack overflow through XMLReader functions

From: Date: Wed, 21 Apr 2021 18:16:59 +0000
Subject: Sec Bug->Bug #73246 [Asn]: Stack overflow through XMLReader functions
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-233546@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73246&edit=1 ID: 73246 Updated by: stas@php.net Reported by: fernando at null-life dot com Summary: Stack overflow through XMLReader functions Status: Assigned -Type: Security +Type: Bug Package: XML Reader Operating System: Linux x64 PHP Version: 7.0.11 Assigned To: stas Block user comment: N Private report: Y New Comment: The null thing doesn't look like security issue. The other thing doesn't look like PHP issue. Let's fix the null thing in 7.4+. Previous Comments: ------------------------------------------------------------------------ [2021-04-21 13:27:02] cmb@php.net More appropriate patch for PHP-7.4: <https://gist.github.com/cmb69/6f8720154c016bfceeee72c400870b48>. IMO, not a security issue. ------------------------------------------------------------------------ [2020-03-18 12:58:45] cmb@php.net The reported stack overflow is certainly not a PHP bug. > encoding length not checked This is a bug, but I'm not sure whether it is a security issue. stas, what do you think? Anyway, fix would be as simple as: ext/xmlreader/php_xmlreader.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/ext/xmlreader/php_xmlreader.c b/ext/xmlreader/php_xmlreader.c index 4d4e7348c9..f920d04eb7 100644 --- a/ext/xmlreader/php_xmlreader.c +++ b/ext/xmlreader/php_xmlreader.c @@ -848,7 +848,7 @@ PHP_METHOD(xmlreader, open) char resolved_path[MAXPATHLEN + 1]; xmlTextReaderPtr reader = NULL; - if (zend_parse_parameters(ZEND_NUM_ARGS(), "p|s!l", &source, &source_len, &encoding, &encoding_len, &options) == FAILURE) { + if (zend_parse_parameters(ZEND_NUM_ARGS(), "p|p!l", &source, &source_len, &encoding, &encoding_len, &options) == FAILURE) { return; } @@ -1033,7 +1033,7 @@ PHP_METHOD(xmlreader, XML) xmlParserInputBufferPtr inputbfr; xmlTextReaderPtr reader; - if (zend_parse_parameters(ZEND_NUM_ARGS(), "s|s!l", &source, &source_len, &encoding, &encoding_len, &options) == FAILURE) { + if (zend_parse_parameters(ZEND_NUM_ARGS(), "s|p!l", &source, &source_len, &encoding, &encoding_len, &options) == FAILURE) { return; } ------------------------------------------------------------------------ [2017-10-17 14:40:17] cmb@php.net iconv_open() is supposed to accept two const char * without any particular restrictions on their length. So, this looks like a bug in the iconv_open() implementation. ------------------------------------------------------------------------ [2016-11-06 19:03:26] fernando at null-life dot com I'm testing on a updated Ubuntu x86_64 Xenial (16.04.1), it's not the last PHP release but AFAIK there has been no changes related to XMLReader to recent PHP versions: Full data environment ---- PHP -------------------------------------------- php --version PHP 7.0.8-0ubuntu0.16.04.3 (cli) ( NTS ) Copyright (c) 1997-2016 The PHP Group Zend Engine v3.0.0, Copyright (c) 1998-2016 Zend Technologies with Zend OPcache v7.0.8-0ubuntu0.16.04.3, Copyright (c) 1999-2016, by Zend Technologies ---- PHP XML --------------------------------------- Package: php7.0-xml Priority: optional Section: php Installed-Size: 468 Maintainer: Ubuntu Developers <ubuntu-devel-discuss@lists.ubuntu.com> Original-Maintainer: Debian PHP Maintainers <pkg-php-maint@lists.alioth.debian.org> Architecture: amd64 Source: php7.0 Version: 7.0.8-0ubuntu0.16.04.3 ---- libxml2 ---------------------------------------- Package: libxml2 Priority: standard Section: libs Installed-Size: 2124 Maintainer: Ubuntu Developers <ubuntu-devel-discuss@lists.ubuntu.com> Original-Maintainer: Debian XML/SGML Group <debian-xml-sgml-pkgs@lists.alioth.debian.org> Architecture: amd64 Version: 2.9.3+dfsg1-1ubuntu0.1 ---- libc ------------------------------------ Package: libc6 Priority: required Section: libs Installed-Size: 10948 Maintainer: Ubuntu Developers <ubuntu-devel-discuss@lists.ubuntu.com> Original-Maintainer: GNU Libc Maintainers <debian-glibc@lists.debian.org> Architecture: amd64 Source: glibc Version: 2.23-0ubuntu4 ---- OS -------------------------------------- cat /etc/os-release NAME="Ubuntu" VERSION="16.04.1 LTS (Xenial Xerus)" ID=ubuntu ID_LIKE=debian PRETTY_NAME="Ubuntu 16.04.1 LTS" VERSION_ID="16.04" HOME_URL="http://www.ubuntu.com/" SUPPORT_URL="http://help.ubuntu.com/" BUG_REPORT_URL="http://bugs.launchpad.net/ubuntu/" VERSION_CODENAME=xenial UBUNTU_CODENAME=xenial ---- Arch --------------------------------------- $ uname -a Linux hp3 4.4.0-21-generic #37-Ubuntu SMP Mon Apr 18 18:33:37 UTC 2016 x86_64 x86_64 x86_64 GNU/Linux ---- PoC --------------------------------------------- $ cat poc.php <?php ini_set('memory_limit', -1); $v = str_repeat("/", 0xffffff/2 - 1); XMLReader::open(".", $v); $ php poc.php Segmentation fault (core dumped) ------------------------------------------------------------------------ [2016-11-04 01:06:36] stas@php.net Failed to reproduce any problem on my system. Maybe a bug in that particular libc build. Does it reproduce on standard PHP build? ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=73246 -- Edit this bug report at https://bugs.php.net/bug.php?id=73246&edit=1

« previous php.bugs (#233546) next »