Sec Bug->Bug #81373 [Opn->Dup]: Segmentation fault

From: Date: Thu, 19 Aug 2021 11:14:18 +0000
Subject: Sec Bug->Bug #81373 [Opn->Dup]: Segmentation fault
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-235949@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81373&edit=1 ID: 81373 Updated by: cmb@php.net Reported by: m dot volkov at npo-echelon dot ru Summary: Segmentation fault -Status: Open +Status: Duplicate -Type: Security +Type: Bug Package: Reproducible crash Operating System: Debian 10 PHP Version: 8.1Git-2021-08-19 (Git) -Assigned To: +Assigned To: cmb Block user comment: N Private report: Y New Comment: Simplified reproducer: <?php class Test { function __toString() { return "$this"; } } $o = new Test; echo $o; ?> This causes a stack overflow due to infinite recursion, and is basically a duplicate of bug #64196. Note that we do not classify this as security issue, because such code is not supposed to ever run in production. See also our security classification[1]. [1] <https://wiki.php.net/security> Previous Comments: ------------------------------------------------------------------------ [2021-08-19 09:11:03] m dot volkov at npo-echelon dot ru Description: ------------ Good afternoon. Fuzzing version 8.1 using AFL. At the moment I have found 9 crashes, all of them cause Segmentation Fault. I did not find any reports about them in the bug reports, so I decided to write, maybe this will help make the PCP safer. In the example below, I indicated one of the cases. Test script: --------------- --TEST-- ZE2 __toString() in __destruct --FILE-- <?php class Test { function __toString() { return "Hel echo $this; } lo\n"; } function __destruct() { echo $this; } } $o = new Test; $o = NULL; $o = new Test; ?> ====DONE==== --E= Hello Expected result: ---------------- exception Actual result: -------------- segmentation fault ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=81373&edit=1

« previous php.bugs (#235949) next »