Sec Bug->Bug #81373 [Opn->Dup]: Segmentation fault
| From: | cmb@php.net | Date: | Thu, 19 Aug 2021 11:14:18 +0000 |
| Subject: | Sec Bug->Bug #81373 [Opn->Dup]: Segmentation fault | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-235949@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=81373&edit=1
ID: 81373
Updated by: cmb@php.net
Reported by: m dot volkov at npo-echelon dot ru
Summary: Segmentation fault
-Status: Open
+Status: Duplicate
-Type: Security
+Type: Bug
Package: Reproducible crash
Operating System: Debian 10
PHP Version: 8.1Git-2021-08-19 (Git)
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: Y
New Comment:
Simplified reproducer:
<?php
class Test
{
function __toString()
{
return "$this";
}
}
$o = new Test;
echo $o;
?>
This causes a stack overflow due to infinite recursion, and is
basically a duplicate of bug #64196. Note that we do not classify
this as security issue, because such code is not supposed to ever
run in production. See also our security classification[1].
[1] <https://wiki.php.net/security>
Previous Comments:
------------------------------------------------------------------------
[2021-08-19 09:11:03] m dot volkov at npo-echelon dot ru
Description:
------------
Good afternoon. Fuzzing version 8.1 using AFL. At the moment I have found 9 crashes, all of them
cause Segmentation Fault. I did not find any reports about them in the bug reports, so I decided to
write, maybe this will help make the PCP safer. In the example below, I indicated one of the cases.
Test script:
---------------
--TEST--
ZE2 __toString() in __destruct
--FILE--
<?php
class Test
{
function __toString()
{
return "Hel echo $this;
}
lo\n";
}
function __destruct()
{
echo $this;
}
}
$o = new Test;
$o = NULL;
$o = new Test;
?>
====DONE====
--E=
Hello
Expected result:
----------------
exception
Actual result:
--------------
segmentation fault
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=81373&edit=1