Bug #81190 [Opn->Csd]: 2 crashes(heap-buffer-overflow,SEGV) 5 memory leaks
| From: | nikic@php.net | Date: | Fri, 02 Jul 2021 08:26:08 +0000 |
| Subject: | Bug #81190 [Opn->Csd]: 2 crashes(heap-buffer-overflow,SEGV) 5 memory leaks | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-234753@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=81190&edit=1
ID: 81190
Updated by: nikic@php.net
Reported by: gutaotao1995 at qq dot com
Summary: 2 crashes(heap-buffer-overflow,SEGV) 5 memory
leaks
-Status: Open
+Status: Closed
Type: Bug
Package: *General Issues
Operating System: linux
PHP Version: 8.1.0alpha1
-Assigned To:
+Assigned To: nikic
Block user comment: N
Private report: N
New Comment:
Looks like crash-eb98564ea8b9e5328defbc17269cfc2c6874d304 is a duplicate of bug #80173, which is now
fixed as well. With that all issues here are fixed, apart from bug #81216, which is tracked
separately.
@gutaotao1995 at qq dot com: I don't see any way to remote exploit any of these issues, because
they require specific malicious code on the server side (rather than, say, specific inputs to
otherwise harmless code). As such, we don't track these as security issues.
Previous Comments:
------------------------------------------------------------------------
[2021-07-01 14:59:18] gutaotao1995 at qq dot com
Thanks for your answer.
After your identification, are these issues of mine a security issue? Doesn't one belong ?
------------------------------------------------------------------------
[2021-07-01 14:46:47] nikic@php.net
crash-php-execute is fixed by https://github.com/php/php-src/commit/353f963bba4f9abcba7d4609e56d0cf2e8af8dfc.
leak-570847a2eeae3e477d2ba8253adb1ca3f78feb26 is a tricky issue for which I don't have an
immediate fix. Filed https://bugs.php.net/bug.php?id=81216 to track it
for now, with some additional information.
@gutaotao1995 at qq dot com: The reductions are just simplified versions of the original inputs.
Regarding CVEs, the PHP project only classifies issues that are potentially remotely expoitable as
security issues, see https://wiki.php.net/security for
the policy.
------------------------------------------------------------------------
[2021-07-01 14:07:49] gutaotao1995 at qq dot com
Thank you very much for your contribution to PHP .
------------------------------------------------------------------------
[2021-07-01 13:56:48] gutaotao1995 at qq dot com
Thank you again for your work, your efficiency is so high!
Can I assign a CVE number to the POC I reported?
------------------------------------------------------------------------
[2021-07-01 13:55:41] gutaotao1995 at qq dot com
Thanks for your work!
Hello, some leak vulnerabilities have been fixed, but they are indeed triggered on the latest
build of oss-fuzz.
Regarding other crashes, such as heap-UAF, have other leak vulnerabilities successfully
reproduced?
In your comment, what does the final "reduction" mean? Please explain to me, is it
impossible to reproduce? Or has it been confirmed as a vulnerability?
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=81190
--
Edit this bug report at https://bugs.php.net/bug.php?id=81190&edit=1