Bug #81707 [Com]: Heap address leak when PHP is configured with libmysql + mariadb
| From: | hndassignmentshelp1 at gmail dot com | Date: | Mon, 14 Feb 2022 07:29:58 +0000 |
| Subject: | Bug #81707 [Com]: Heap address leak when PHP is configured with libmysql + mariadb | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-239755@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=81707&edit=1
ID: 81707
Comment by: hndassignmentshelp1 at gmail dot com
Reported by: ive_jihwan at zerocution dot com
Summary: Heap address leak when PHP is configured with
libmysql + mariadb
Status: Open
Type: Bug
Package: MySQLi related
Operating System: WSL
PHP Version: Irrelevant
Block user comment: N
Private report: N
New Comment:
Driscoll Model of Reflection
Get Driscoll Model of Reflection Assignment Help by www.hndassignmenthelp.com at Affordable Price
and Quality Delivery on Time. We have more than 7000+ Qualified British Experts in the team to give
you the best online assignment help in the HND Assignment Help of Driscoll reflective model.
https://www.hndassignmenthelp.com/driscoll-model-of-reflection-by-hnd-assignment-help/
hndassignmenthelp, assignmenthelponline, driscollmodelofreflection, driscollreflectivemodel
Previous Comments:
------------------------------------------------------------------------
[2022-01-19 06:36:08] ive_jihwan at zerocution dot com
Description:
------------
When PHP is configured with libmysql instead of mysqlnd, there is a possibility to leak emalloc()ed
address via simple SQL query with bind_result and fetch.
This only copies the lower 4 bytes of the address, but since the MSB is fixed as 0x7f, it's
reasonable to find a full heap address.
I tested this in WSL + MariaDB 10.5.13 + PHP 8.2.0-dev with libmysql build
Test script:
---------------
<?php
$mysqli = new mysqli("127.0.0.1", "test", "%");
$stmt = $mysqli->prepare("select 1");
$stmt->bind_result($a);
$stmt->prepare("select 1");
$stmt->execute();
$stmt->fetch();
echo "$a"; // the lowest 4 bytes of heap structure
if (!($a & (int)0xffffffff00000000)) {
printf("Failed, try again\n");
die();
}
printf("Address in heap leaked: 0x7fff%x\n", $a & 0xffffffff);
Expected result:
----------------
Should return 1 or 0
Actual result:
--------------
the lower 4 bytes of (int *)stmt->result.buf[0].val
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=81707&edit=1