Bug #76244 [Opn->Wfx]: A stack overflow vulnerability exist (most likely) in the isSet function
| From: | cmb@php.net | Date: | Fri, 28 May 2021 14:53:16 +0000 |
| Subject: | Bug #76244 [Opn->Wfx]: A stack overflow vulnerability exist (most likely) in the isSet function | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-234076@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=76244&edit=1
ID: 76244
Updated by: cmb@php.net
Reported by: daniel dot teuchert at rub dot de
Summary: A stack overflow vulnerability exist (most likely)
in the isSet function
-Status: Open
+Status: Wont fix
Type: Bug
-Package: *Programming Data Structures
+Package: Scripting Engine problem
Operating System: Linux 4.6.2
PHP Version: 7.2.4
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Actually, this looks like a recursion issue during parsing; I
don't think we want to "improve" the parser to handle such
pathological code.
Previous Comments:
------------------------------------------------------------------------
[2018-04-23 03:34:29] stas@php.net
Not a security issue, please see https://wiki.php.net/security
------------------------------------------------------------------------
[2018-04-22 22:16:08] cmb@php.net
This does not look like a security issue, since checking so many
variables in a single isset() does not appear to be of any
practical purpose.
------------------------------------------------------------------------
[2018-04-20 11:12:10] daniel dot teuchert at rub dot de
Description:
------------
Calling isSet with too many parameters causes a stack overflow.
Executing the test script results in a stack overflow.
The produced ASAN output can be found here: https://github.com/pnoltof/php_bug/blob/master/ASAN_output.txt
An attacker can possibly use this flaw to execute arbitrary code.
Steps to reproduce:
Build latest php version (compile with ASAN)
Donwload PoC file called "stack_overflow" (see Test script)
Execute binary file in $WORKDIR/php-7.2.4/sapi/cli/:
$WORKDIR/php-7.2.4/sapi/cli/php stack_overflow
I was not able to reproduce this behavior when debugging with gdb.
Test script:
---------------
PoC file can be found here: https://github.com/pnoltof/php_bug/blob/master/stack_overflow
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=76244&edit=1