SEBUG-ID: 1491SEBUG-Appdir: PHP
Release date: 2007-03-17
Affected Versions:
PHP 5.2.1
PHP 5.1.6
PHP 5.1.5
PHP 5.1.4
PHP 5.1.3
PHP 5.1.3
PHP 5.1.2
PHP 5.1.1
PHP 5.1
PHP 5.0.5
PHP 5.0.4
PHP 5.0.3
+ Trustix Secure Linux 2.2
PHP 5.0.2
PHP 5.0.1
PHP 5.0 candidate 3
PHP 5.0 candidate 2
PHP 5.0 candidate 1
PHP 5.0. 0
PHP 5.2
Vulnerability description:
PHP is a widely used WEB development scripting language.
PHP Session_Regenerate_ID function has the issue of double-release content destruction. Remote attackers can exploit this vulnerability to launch DoS attacks on applications, which may lead to arbitrary command execution.
The session_regenerate_id () function first releases the old session identifier and immediately allocates new values generated by the session recognition generator:
Copy codeThe Code is as follows:
PHP_FUNCTION (session_regenerate_id)
{
...
If (PS (id )){
...
Efree (PS (id ));
}
PS (id) = PS (mod)-> s_create_sid (& PS (mod_data), NULL TSRMLS_CC );
PS (send_cookie) = 1;
Php_session_reset_id (TSRMLS_C );
RETURN_TRUE;
}
RETURN_FALSE;
}
However, this allocation operation is not an atomic operation. Therefore, it can be interrupted by operations such as memory limit conflicts. In addition, according to the PHP configuration, the generator can trigger a PHP error and cause an interruption.
Copy codeThe Code is as follows:
PHPAPI char * php_session_create_id (PS_CREATE_SID_ARGS)
{
...
Switch (PS (hash_func )){
...
Default:
Php_error_docref (NULL TSRMLS_CC, E_ERROR, "Invalid session hash function ");
Efree (buf );
Return NULL;
}
...
If (PS (hash_bits_per_character) <4
| PS (hash_bits_per_character)> 6 ){
PS (hash_bits_per_character) = 4;
Php_error_docref (NULL TSRMLS_CC, E_WARNING, "The ini setting hash_bits_per_character ...");
}
...
This issue can be easily exploited by registering a malicious user space error processor. When the processor calls a HASH table and assigns it to the same location as the previous session identifier, then the malicious error processor can call the session_id () function and assign a HASH table containing the forged HASH table to the same location as the HASH table, in this way, the release operation of another previous session identifier is triggered. After the error processor is complete, the user will deconstruct the covered HASH table and call the code provided by the attacker.
Http://www.php-security.org/MOPB/MOPB-22-2007.html
Test method:
[Www.sebug.net]
The Program (method) provided on this site may be offensive and only used for security research and teaching. You are at your own risk!
Http://www.php-security.org/MOPB/code/MOPB-22-2007.php
SEBUG Security suggestions:
Currently, no solutions are available: