af9dc8
From 2fefae47716d501aec41c1102f3fd4531f070b05 Mon Sep 17 00:00:00 2001
af9dc8
From: Remi Collet <remi@php.net>
af9dc8
Date: Tue, 19 Aug 2014 08:33:49 +0200
af9dc8
Subject: [PATCH] Fixed Sec Bug #67717 segfault in dns_get_record CVE-2014-3597
af9dc8
af9dc8
Incomplete fix for CVE-2014-4049
af9dc8
af9dc8
Check possible buffer overflow
af9dc8
- pass real buffer end to dn_expand calls
af9dc8
- check buffer len before each read
af9dc8
---
af9dc8
 ext/standard/dns.c | 84 ++++++++++++++++++++++++++++++++++++++----------------
af9dc8
 1 file changed, 60 insertions(+), 24 deletions(-)
af9dc8
af9dc8
diff --git a/ext/standard/dns.c b/ext/standard/dns.c
af9dc8
index 214a7dc..0b5e69c 100644
af9dc8
--- a/ext/standard/dns.c
af9dc8
+++ b/ext/standard/dns.c
af9dc8
@@ -412,8 +412,14 @@ PHP_FUNCTION(dns_check_record)
af9dc8
 
af9dc8
 #if HAVE_FULL_DNS_FUNCS
af9dc8
 
af9dc8
+#define CHECKCP(n) do { \
af9dc8
+	if (cp + n > end) { \
af9dc8
+		return NULL; \
af9dc8
+	} \
af9dc8
+} while (0)
af9dc8
+
af9dc8
 /* {{{ php_parserr */
af9dc8
-static u_char *php_parserr(u_char *cp, querybuf *answer, int type_to_fetch, int store, int raw, zval **subarray)
af9dc8
+static u_char *php_parserr(u_char *cp, u_char *end, querybuf *answer, int type_to_fetch, int store, int raw, zval **subarray)
af9dc8
 {
af9dc8
 	u_short type, class, dlen;
af9dc8
 	u_long ttl;
af9dc8
@@ -425,16 +431,18 @@ static u_char *php_parserr(u_char *cp, querybuf *answer, int type_to_fetch, int
af9dc8
 
af9dc8
 	*subarray = NULL;
af9dc8
 
af9dc8
-	n = dn_expand(answer->qb2, answer->qb2+65536, cp, name, sizeof(name) - 2);
af9dc8
+	n = dn_expand(answer->qb2, end, cp, name, sizeof(name) - 2);
af9dc8
 	if (n < 0) {
af9dc8
 		return NULL;
af9dc8
 	}
af9dc8
 	cp += n;
af9dc8
 
af9dc8
+	CHECKCP(10);
af9dc8
 	GETSHORT(type, cp);
af9dc8
 	GETSHORT(class, cp);
af9dc8
 	GETLONG(ttl, cp);
af9dc8
 	GETSHORT(dlen, cp);
af9dc8
+	CHECKCP(dlen);
af9dc8
 	if (type_to_fetch != T_ANY && type != type_to_fetch) {
af9dc8
 		cp += dlen;
af9dc8
 		return cp;
af9dc8
@@ -461,12 +469,14 @@ static u_char *php_parserr(u_char *cp, querybuf *answer, int type_to_fetch, int
af9dc8
 
af9dc8
 	switch (type) {
af9dc8
 		case DNS_T_A:
af9dc8
+			CHECKCP(4);
af9dc8
 			add_assoc_string(*subarray, "type", "A", 1);
af9dc8
 			snprintf(name, sizeof(name), "%d.%d.%d.%d", cp[0], cp[1], cp[2], cp[3]);
af9dc8
 			add_assoc_string(*subarray, "ip", name, 1);
af9dc8
 			cp += dlen;
af9dc8
 			break;
af9dc8
 		case DNS_T_MX:
af9dc8
+			CHECKCP(2);
af9dc8
 			add_assoc_string(*subarray, "type", "MX", 1);
af9dc8
 			GETSHORT(n, cp);
af9dc8
 			add_assoc_long(*subarray, "pri", n);
af9dc8
@@ -485,7 +495,7 @@ static u_char *php_parserr(u_char *cp, querybuf *answer, int type_to_fetch, int
af9dc8
 			if (type == DNS_T_PTR) {
af9dc8
 				add_assoc_string(*subarray, "type", "PTR", 1);
af9dc8
 			}
af9dc8
-			n = dn_expand(answer->qb2, answer->qb2+65536, cp, name, (sizeof name) - 2);
af9dc8
+			n = dn_expand(answer->qb2, end, cp, name, (sizeof name) - 2);
af9dc8
 			if (n < 0) {
af9dc8
 				return NULL;
af9dc8
 			}
af9dc8
@@ -495,18 +505,22 @@ static u_char *php_parserr(u_char *cp, querybuf *answer, int type_to_fetch, int
af9dc8
 		case DNS_T_HINFO:
af9dc8
 			/* See RFC 1010 for values */
af9dc8
 			add_assoc_string(*subarray, "type", "HINFO", 1);
af9dc8
+			CHECKCP(1);
af9dc8
 			n = *cp & 0xFF;
af9dc8
 			cp++;
af9dc8
+			CHECKCP(n);
af9dc8
 			add_assoc_stringl(*subarray, "cpu", (char*)cp, n, 1);
af9dc8
 			cp += n;
af9dc8
+			CHECKCP(1);
af9dc8
 			n = *cp & 0xFF;
af9dc8
 			cp++;
af9dc8
+			CHECKCP(n);
af9dc8
 			add_assoc_stringl(*subarray, "os", (char*)cp, n, 1);
af9dc8
 			cp += n;
af9dc8
 			break;
af9dc8
 		case DNS_T_TXT:
af9dc8
 			{
af9dc8
-				int ll = 0;
af9dc8
+				int l1 = 0, l2 = 0;
af9dc8
 				zval *entries = NULL;
af9dc8
 
af9dc8
 				add_assoc_string(*subarray, "type", "TXT", 1);
af9dc8
@@ -515,37 +529,41 @@ static u_char *php_parserr(u_char *cp, querybuf *answer, int type_to_fetch, int
af9dc8
 				MAKE_STD_ZVAL(entries);
af9dc8
 				array_init(entries);
af9dc8
 				
af9dc8
-				while (ll < dlen) {
af9dc8
-					n = cp[ll];
af9dc8
-					if ((ll + n) >= dlen) {
af9dc8
+				while (l1 < dlen) {
af9dc8
+					n = cp[l1];
af9dc8
+					if ((l1 + n) >= dlen) {
af9dc8
 						// Invalid chunk length, truncate
af9dc8
-						n = dlen - (ll + 1);
af9dc8
+						n = dlen - (l1 + 1);
af9dc8
+					}
af9dc8
+					if (n) {
af9dc8
+						memcpy(tp + l2 , cp + l1 + 1, n);
af9dc8
+						add_next_index_stringl(entries, cp + l1 + 1, n, 1);
af9dc8
 					}
af9dc8
-					memcpy(tp + ll , cp + ll + 1, n);
af9dc8
-					add_next_index_stringl(entries, cp + ll + 1, n, 1);
af9dc8
-					ll = ll + n + 1;
af9dc8
+					l1 = l1 + n + 1;
af9dc8
+					l2 = l2 + n;
af9dc8
 				}
af9dc8
-				tp[dlen] = '\0';
af9dc8
+				tp[l2] = '\0';
af9dc8
 				cp += dlen;
af9dc8
 
af9dc8
-				add_assoc_stringl(*subarray, "txt", tp, (dlen>0)?dlen - 1:0, 0);
af9dc8
+				add_assoc_stringl(*subarray, "txt", tp, l2, 0);
af9dc8
 				add_assoc_zval(*subarray, "entries", entries);
af9dc8
 			}
af9dc8
 			break;
af9dc8
 		case DNS_T_SOA:
af9dc8
 			add_assoc_string(*subarray, "type", "SOA", 1);
af9dc8
-			n = dn_expand(answer->qb2, answer->qb2+65536, cp, name, (sizeof name) -2);
af9dc8
+			n = dn_expand(answer->qb2, end, cp, name, (sizeof name) -2);
af9dc8
 			if (n < 0) {
af9dc8
 				return NULL;
af9dc8
 			}
af9dc8
 			cp += n;
af9dc8
 			add_assoc_string(*subarray, "mname", name, 1);
af9dc8
-			n = dn_expand(answer->qb2, answer->qb2+65536, cp, name, (sizeof name) -2);
af9dc8
+			n = dn_expand(answer->qb2, end, cp, name, (sizeof name) -2);
af9dc8
 			if (n < 0) {
af9dc8
 				return NULL;
af9dc8
 			}
af9dc8
 			cp += n;
af9dc8
 			add_assoc_string(*subarray, "rname", name, 1);
af9dc8
+			CHECKCP(5*4);
af9dc8
 			GETLONG(n, cp);
af9dc8
 			add_assoc_long(*subarray, "serial", n);
af9dc8
 			GETLONG(n, cp);
af9dc8
@@ -559,6 +577,7 @@ static u_char *php_parserr(u_char *cp, querybuf *answer, int type_to_fetch, int
af9dc8
 			break;
af9dc8
 		case DNS_T_AAAA:
af9dc8
 			tp = (u_char*)name;
af9dc8
+			CHECKCP(8*2);
af9dc8
 			for(i=0; i < 8; i++) {
af9dc8
 				GETSHORT(s, cp);
af9dc8
 				if (s != 0) {
af9dc8
@@ -593,6 +612,7 @@ static u_char *php_parserr(u_char *cp, querybuf *answer, int type_to_fetch, int
af9dc8
 		case DNS_T_A6:
af9dc8
 			p = cp;
af9dc8
 			add_assoc_string(*subarray, "type", "A6", 1);
af9dc8
+			CHECKCP(1);
af9dc8
 			n = ((int)cp[0]) & 0xFF;
af9dc8
 			cp++;
af9dc8
 			add_assoc_long(*subarray, "masklen", n);
af9dc8
@@ -628,6 +648,7 @@ static u_char *php_parserr(u_char *cp, querybuf *answer, int type_to_fetch, int
af9dc8
 				cp++;
af9dc8
 			}
af9dc8
 			for (i = (n + 8) / 16; i < 8; i++) {
af9dc8
+				CHECKCP(2);
af9dc8
 				GETSHORT(s, cp);
af9dc8
 				if (s != 0) {
af9dc8
 					if (tp > (u_char *)name) {
af9dc8
@@ -657,7 +678,7 @@ static u_char *php_parserr(u_char *cp, querybuf *answer, int type_to_fetch, int
af9dc8
 			tp[0] = '\0';
af9dc8
 			add_assoc_string(*subarray, "ipv6", name, 1);
af9dc8
 			if (cp < p + dlen) {
af9dc8
-				n = dn_expand(answer->qb2, answer->qb2+65536, cp, name, (sizeof name) - 2);
af9dc8
+				n = dn_expand(answer->qb2, end, cp, name, (sizeof name) - 2);
af9dc8
 				if (n < 0) {
af9dc8
 					return NULL;
af9dc8
 				}
af9dc8
@@ -666,6 +687,7 @@ static u_char *php_parserr(u_char *cp, querybuf *answer, int type_to_fetch, int
af9dc8
 			}
af9dc8
 			break;
af9dc8
 		case DNS_T_SRV:
af9dc8
+			CHECKCP(3*2);
af9dc8
 			add_assoc_string(*subarray, "type", "SRV", 1);
af9dc8
 			GETSHORT(n, cp);
af9dc8
 			add_assoc_long(*subarray, "pri", n);
af9dc8
@@ -673,7 +695,7 @@ static u_char *php_parserr(u_char *cp, querybuf *answer, int type_to_fetch, int
af9dc8
 			add_assoc_long(*subarray, "weight", n);
af9dc8
 			GETSHORT(n, cp);
af9dc8
 			add_assoc_long(*subarray, "port", n);
af9dc8
-			n = dn_expand(answer->qb2, answer->qb2+65536, cp, name, (sizeof name) - 2);
af9dc8
+			n = dn_expand(answer->qb2, end, cp, name, (sizeof name) - 2);
af9dc8
 			if (n < 0) {
af9dc8
 				return NULL;
af9dc8
 			}
af9dc8
@@ -681,21 +703,35 @@ static u_char *php_parserr(u_char *cp, querybuf *answer, int type_to_fetch, int
af9dc8
 			add_assoc_string(*subarray, "target", name, 1);
af9dc8
 			break;
af9dc8
 		case DNS_T_NAPTR:
af9dc8
+			CHECKCP(2*2);
af9dc8
 			add_assoc_string(*subarray, "type", "NAPTR", 1);
af9dc8
 			GETSHORT(n, cp);
af9dc8
 			add_assoc_long(*subarray, "order", n);
af9dc8
 			GETSHORT(n, cp);
af9dc8
 			add_assoc_long(*subarray, "pref", n);
af9dc8
+
af9dc8
+			CHECKCP(1);
af9dc8
 			n = (cp[0] & 0xFF);
af9dc8
-			add_assoc_stringl(*subarray, "flags", (char*)++cp, n, 1);
af9dc8
+			cp++;
af9dc8
+			CHECKCP(n);
af9dc8
+			add_assoc_stringl(*subarray, "flags", (char*)cp, n, 1);
af9dc8
 			cp += n;
af9dc8
+
af9dc8
+			CHECKCP(1);
af9dc8
 			n = (cp[0] & 0xFF);
af9dc8
-			add_assoc_stringl(*subarray, "services", (char*)++cp, n, 1);
af9dc8
+			cp++;
af9dc8
+			CHECKCP(n);
af9dc8
+			add_assoc_stringl(*subarray, "services", (char*)cp, n, 1);
af9dc8
 			cp += n;
af9dc8
+
af9dc8
+			CHECKCP(1);
af9dc8
 			n = (cp[0] & 0xFF);
af9dc8
-			add_assoc_stringl(*subarray, "regex", (char*)++cp, n, 1);
af9dc8
+			cp++;
af9dc8
+			CHECKCP(n);
af9dc8
+			add_assoc_stringl(*subarray, "regex", (char*)cp, n, 1);
af9dc8
 			cp += n;
af9dc8
-			n = dn_expand(answer->qb2, answer->qb2+65536, cp, name, (sizeof name) - 2);
af9dc8
+
af9dc8
+			n = dn_expand(answer->qb2, end, cp, name, (sizeof name) - 2);
af9dc8
 			if (n < 0) {
af9dc8
 				return NULL;
af9dc8
 			}
af9dc8
@@ -888,7 +924,7 @@ PHP_FUNCTION(dns_get_record)
af9dc8
 			while (an-- && cp && cp < end) {
af9dc8
 				zval *retval;
af9dc8
 
af9dc8
-				cp = php_parserr(cp, &answer, type_to_fetch, store_results, raw, &retval);
af9dc8
+				cp = php_parserr(cp, end, &answer, type_to_fetch, store_results, raw, &retval);
af9dc8
 				if (retval != NULL && store_results) {
af9dc8
 					add_next_index_zval(return_value, retval);
af9dc8
 				}
af9dc8
@@ -901,7 +937,7 @@ PHP_FUNCTION(dns_get_record)
af9dc8
 				while (ns-- > 0 && cp && cp < end) {
af9dc8
 					zval *retval = NULL;
af9dc8
 
af9dc8
-					cp = php_parserr(cp, &answer, DNS_T_ANY, authns != NULL, raw, &retval);
af9dc8
+					cp = php_parserr(cp, end, &answer, DNS_T_ANY, authns != NULL, raw, &retval);
af9dc8
 					if (retval != NULL) {
af9dc8
 						add_next_index_zval(authns, retval);
af9dc8
 					}
af9dc8
@@ -913,7 +949,7 @@ PHP_FUNCTION(dns_get_record)
af9dc8
 				while (ar-- > 0 && cp && cp < end) {
af9dc8
 					zval *retval = NULL;
af9dc8
 
af9dc8
-					cp = php_parserr(cp, &answer, DNS_T_ANY, 1, raw, &retval);
af9dc8
+					cp = php_parserr(cp, end, &answer, DNS_T_ANY, 1, raw, &retval);
af9dc8
 					if (retval != NULL) {
af9dc8
 						add_next_index_zval(addtl, retval);
af9dc8
 					}
af9dc8
-- 
af9dc8
1.9.2
af9dc8