Sec Bug->Bug #73246 [Asn]: Stack overflow through XMLReader functions
| From: | stas@php.net | Date: | Wed, 21 Apr 2021 18:16:59 +0000 |
| Subject: | Sec Bug->Bug #73246 [Asn]: Stack overflow through XMLReader functions | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-233546@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=73246&edit=1
ID: 73246
Updated by: stas@php.net
Reported by: fernando at null-life dot com
Summary: Stack overflow through XMLReader functions
Status: Assigned
-Type: Security
+Type: Bug
Package: XML Reader
Operating System: Linux x64
PHP Version: 7.0.11
Assigned To: stas
Block user comment: N
Private report: Y
New Comment:
The null thing doesn't look like security issue. The other thing doesn't look like PHP
issue. Let's fix the null thing in 7.4+.
Previous Comments:
------------------------------------------------------------------------
[2021-04-21 13:27:02] cmb@php.net
More appropriate patch for PHP-7.4:
<https://gist.github.com/cmb69/6f8720154c016bfceeee72c400870b48>.
IMO, not a security issue.
------------------------------------------------------------------------
[2020-03-18 12:58:45] cmb@php.net
The reported stack overflow is certainly not a PHP bug.
> encoding length not checked
This is a bug, but I'm not sure whether it is a security issue.
stas, what do you think?
Anyway, fix would be as simple as:
ext/xmlreader/php_xmlreader.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/ext/xmlreader/php_xmlreader.c b/ext/xmlreader/php_xmlreader.c
index 4d4e7348c9..f920d04eb7 100644
--- a/ext/xmlreader/php_xmlreader.c
+++ b/ext/xmlreader/php_xmlreader.c
@@ -848,7 +848,7 @@ PHP_METHOD(xmlreader, open)
char resolved_path[MAXPATHLEN + 1];
xmlTextReaderPtr reader = NULL;
- if (zend_parse_parameters(ZEND_NUM_ARGS(), "p|s!l", &source, &source_len,
&encoding, &encoding_len, &options) == FAILURE) {
+ if (zend_parse_parameters(ZEND_NUM_ARGS(), "p|p!l", &source, &source_len,
&encoding, &encoding_len, &options) == FAILURE) {
return;
}
@@ -1033,7 +1033,7 @@ PHP_METHOD(xmlreader, XML)
xmlParserInputBufferPtr inputbfr;
xmlTextReaderPtr reader;
- if (zend_parse_parameters(ZEND_NUM_ARGS(), "s|s!l", &source, &source_len,
&encoding, &encoding_len, &options) == FAILURE) {
+ if (zend_parse_parameters(ZEND_NUM_ARGS(), "s|p!l", &source, &source_len,
&encoding, &encoding_len, &options) == FAILURE) {
return;
}
------------------------------------------------------------------------
[2017-10-17 14:40:17] cmb@php.net
iconv_open() is supposed to accept two const char * without any particular
restrictions on their length. So, this looks like a bug in the iconv_open()
implementation.
------------------------------------------------------------------------
[2016-11-06 19:03:26] fernando at null-life dot com
I'm testing on a updated Ubuntu x86_64 Xenial (16.04.1), it's not the last PHP release but
AFAIK there has been no changes related to XMLReader to recent PHP versions:
Full data environment
---- PHP --------------------------------------------
php --version
PHP 7.0.8-0ubuntu0.16.04.3 (cli) ( NTS )
Copyright (c) 1997-2016 The PHP Group
Zend Engine v3.0.0, Copyright (c) 1998-2016 Zend Technologies
with Zend OPcache v7.0.8-0ubuntu0.16.04.3, Copyright (c) 1999-2016, by Zend Technologies
---- PHP XML ---------------------------------------
Package: php7.0-xml
Priority: optional
Section: php
Installed-Size: 468
Maintainer: Ubuntu Developers <ubuntu-devel-discuss@lists.ubuntu.com>
Original-Maintainer: Debian PHP Maintainers <pkg-php-maint@lists.alioth.debian.org>
Architecture: amd64
Source: php7.0
Version: 7.0.8-0ubuntu0.16.04.3
---- libxml2 ----------------------------------------
Package: libxml2
Priority: standard
Section: libs
Installed-Size: 2124
Maintainer: Ubuntu Developers <ubuntu-devel-discuss@lists.ubuntu.com>
Original-Maintainer: Debian XML/SGML Group <debian-xml-sgml-pkgs@lists.alioth.debian.org>
Architecture: amd64
Version: 2.9.3+dfsg1-1ubuntu0.1
---- libc ------------------------------------
Package: libc6
Priority: required
Section: libs
Installed-Size: 10948
Maintainer: Ubuntu Developers <ubuntu-devel-discuss@lists.ubuntu.com>
Original-Maintainer: GNU Libc Maintainers <debian-glibc@lists.debian.org>
Architecture: amd64
Source: glibc
Version: 2.23-0ubuntu4
---- OS --------------------------------------
cat /etc/os-release
NAME="Ubuntu"
VERSION="16.04.1 LTS (Xenial Xerus)"
ID=ubuntu
ID_LIKE=debian
PRETTY_NAME="Ubuntu 16.04.1 LTS"
VERSION_ID="16.04"
HOME_URL="http://www.ubuntu.com/"
SUPPORT_URL="http://help.ubuntu.com/"
BUG_REPORT_URL="http://bugs.launchpad.net/ubuntu/"
VERSION_CODENAME=xenial
UBUNTU_CODENAME=xenial
---- Arch ---------------------------------------
$ uname -a
Linux hp3 4.4.0-21-generic #37-Ubuntu SMP Mon Apr 18 18:33:37 UTC 2016 x86_64 x86_64 x86_64
GNU/Linux
---- PoC ---------------------------------------------
$ cat poc.php
<?php
ini_set('memory_limit', -1);
$v = str_repeat("/", 0xffffff/2 - 1);
XMLReader::open(".", $v);
$ php poc.php
Segmentation fault (core dumped)
------------------------------------------------------------------------
[2016-11-04 01:06:36] stas@php.net
Failed to reproduce any problem on my system. Maybe a bug in that particular libc build. Does it
reproduce on standard PHP build?
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=73246
--
Edit this bug report at https://bugs.php.net/bug.php?id=73246&edit=1