Bug #81190 [Opn->Csd]: 2 crashes(heap-buffer-overflow,SEGV) 5 memory leaks

From: Date: Fri, 02 Jul 2021 08:26:08 +0000
Subject: Bug #81190 [Opn->Csd]: 2 crashes(heap-buffer-overflow,SEGV) 5 memory leaks
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-234753@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81190&edit=1 ID: 81190 Updated by: nikic@php.net Reported by: gutaotao1995 at qq dot com Summary: 2 crashes(heap-buffer-overflow,SEGV) 5 memory leaks -Status: Open +Status: Closed Type: Bug Package: *General Issues Operating System: linux PHP Version: 8.1.0alpha1 -Assigned To: +Assigned To: nikic Block user comment: N Private report: N New Comment: Looks like crash-eb98564ea8b9e5328defbc17269cfc2c6874d304 is a duplicate of bug #80173, which is now fixed as well. With that all issues here are fixed, apart from bug #81216, which is tracked separately. @gutaotao1995 at qq dot com: I don't see any way to remote exploit any of these issues, because they require specific malicious code on the server side (rather than, say, specific inputs to otherwise harmless code). As such, we don't track these as security issues. Previous Comments: ------------------------------------------------------------------------ [2021-07-01 14:59:18] gutaotao1995 at qq dot com Thanks for your answer. After your identification, are these issues of mine a security issue? Doesn't one belong ? ------------------------------------------------------------------------ [2021-07-01 14:46:47] nikic@php.net crash-php-execute is fixed by https://github.com/php/php-src/commit/353f963bba4f9abcba7d4609e56d0cf2e8af8dfc. leak-570847a2eeae3e477d2ba8253adb1ca3f78feb26 is a tricky issue for which I don't have an immediate fix. Filed https://bugs.php.net/bug.php?id=81216 to track it for now, with some additional information. @gutaotao1995 at qq dot com: The reductions are just simplified versions of the original inputs. Regarding CVEs, the PHP project only classifies issues that are potentially remotely expoitable as security issues, see https://wiki.php.net/security for the policy. ------------------------------------------------------------------------ [2021-07-01 14:07:49] gutaotao1995 at qq dot com Thank you very much for your contribution to PHP . ------------------------------------------------------------------------ [2021-07-01 13:56:48] gutaotao1995 at qq dot com Thank you again for your work, your efficiency is so high! Can I assign a CVE number to the POC I reported? ------------------------------------------------------------------------ [2021-07-01 13:55:41] gutaotao1995 at qq dot com Thanks for your work! Hello, some leak vulnerabilities have been fixed, but they are indeed triggered on the latest build of oss-fuzz. Regarding other crashes, such as heap-UAF, have other leak vulnerabilities successfully reproduced? In your comment, what does the final "reduction" mean? Please explain to me, is it impossible to reproduce? Or has it been confirmed as a vulnerability? ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=81190 -- Edit this bug report at https://bugs.php.net/bug.php?id=81190&edit=1

« previous php.bugs (#234753) next »