Bug #76244 [Opn->Wfx]: A stack overflow vulnerability exist (most likely) in the isSet function

From: Date: Fri, 28 May 2021 14:53:16 +0000
Subject: Bug #76244 [Opn->Wfx]: A stack overflow vulnerability exist (most likely) in the isSet function
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-234076@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76244&edit=1 ID: 76244 Updated by: cmb@php.net Reported by: daniel dot teuchert at rub dot de Summary: A stack overflow vulnerability exist (most likely) in the isSet function -Status: Open +Status: Wont fix Type: Bug -Package: *Programming Data Structures +Package: Scripting Engine problem Operating System: Linux 4.6.2 PHP Version: 7.2.4 -Assigned To: +Assigned To: cmb Block user comment: N Private report: N New Comment: Actually, this looks like a recursion issue during parsing; I don't think we want to "improve" the parser to handle such pathological code. Previous Comments: ------------------------------------------------------------------------ [2018-04-23 03:34:29] stas@php.net Not a security issue, please see https://wiki.php.net/security ------------------------------------------------------------------------ [2018-04-22 22:16:08] cmb@php.net This does not look like a security issue, since checking so many variables in a single isset() does not appear to be of any practical purpose. ------------------------------------------------------------------------ [2018-04-20 11:12:10] daniel dot teuchert at rub dot de Description: ------------ Calling isSet with too many parameters causes a stack overflow. Executing the test script results in a stack overflow. The produced ASAN output can be found here: https://github.com/pnoltof/php_bug/blob/master/ASAN_output.txt An attacker can possibly use this flaw to execute arbitrary code. Steps to reproduce: Build latest php version (compile with ASAN) Donwload PoC file called "stack_overflow" (see Test script) Execute binary file in $WORKDIR/php-7.2.4/sapi/cli/: $WORKDIR/php-7.2.4/sapi/cli/php stack_overflow I was not able to reproduce this behavior when debugging with gdb. Test script: --------------- PoC file can be found here: https://github.com/pnoltof/php_bug/blob/master/stack_overflow ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=76244&edit=1

« previous php.bugs (#234076) next »