diff --git a/.github/scripts/windows/test_task.bat b/.github/scripts/windows/test_task.bat index 7c526be95c3d..6c49ebe40417 100644 --- a/.github/scripts/windows/test_task.bat +++ b/.github/scripts/windows/test_task.bat @@ -117,8 +117,9 @@ set PHP_BUILD_DIR=%PHP_BUILD_OBJ_DIR%\Release if "%THREAD_SAFE%" equ "1" set PHP_BUILD_DIR=%PHP_BUILD_DIR%_TS rem prepare for mail -curl -sLo hMailServer.exe https://www.hmailserver.com/download_file/?downloadid=271 -hMailServer.exe /verysilent +curl -sLo hMailServer.zip https://downloads.php.net/~windows/php-sdk/deps/vs18/x64/hmailserver-5.7.0-vs18-x64.zip +unzip -q hMailServer.zip -d hMailServer +hMailServer\bin\hMailServer.exe /verysilent cd %APPVEYOR_BUILD_FOLDER% %PHP_BUILD_DIR%\php.exe -dextension_dir=%PHP_BUILD_DIR% -dextension=com_dotnet .github\setup_hmailserver.php diff --git a/NEWS b/NEWS index 378643836c80..06f35fa08ee4 100644 --- a/NEWS +++ b/NEWS @@ -37,6 +37,15 @@ PHP NEWS . Fixed segfault in ReflectionMethod::createFromMethodName() on an uninstantiable subclass. (iliaal) +- Session: + . Fix corruption in mod_mm. (ndossche) + . Fixed bug GH-23043 (broken session id code can cause zend_mm_heap + corrupted). (ndossche) + +- SimpleXML: + . Fixed SimpleXMLElement::__construct() accepting embedded null bytes in + URL/path mode. (iliaal) + - Sockets: . Fixed various memory related issues in ext/sockets. (David Carlier) diff --git a/ext/session/mod_mm.c b/ext/session/mod_mm.c index b997a2bdcff5..75ee713e9f09 100644 --- a/ext/session/mod_mm.c +++ b/ext/session/mod_mm.c @@ -351,7 +351,7 @@ PS_READ_FUNC(mm) && ps_mm_key_exists(data, key) == FAILURE) { /* key points to PS(id), but cannot change here. */ if (key) { - efree(PS(id)); + zend_string_release_ex(PS(id), false); PS(id) = NULL; } PS(id) = PS(mod)->s_create_sid((void **)&data); diff --git a/ext/session/session.c b/ext/session/session.c index ba71d709a536..6380505ae951 100644 --- a/ext/session/session.c +++ b/ext/session/session.c @@ -443,6 +443,7 @@ static zend_result php_session_initialize(void) /* {{{ */ if (!PS(id) || !ZSTR_VAL(PS(id))[0]) { if (PS(id)) { zend_string_release_ex(PS(id), 0); + PS(id) = NULL; } PS(id) = PS(mod)->s_create_sid(&PS(mod_data)); if (!PS(id)) { @@ -460,6 +461,7 @@ static zend_result php_session_initialize(void) /* {{{ */ ) { if (PS(id)) { zend_string_release_ex(PS(id), 0); + PS(id) = NULL; } PS(id) = PS(mod)->s_create_sid(&PS(mod_data)); if (!PS(id)) { @@ -2440,6 +2442,7 @@ PHP_FUNCTION(session_regenerate_id) /* Try to generate non-existing ID */ while (limit-- && PS(mod)->s_validate_sid(&PS(mod_data), PS(id)) == SUCCESS) { zend_string_release_ex(PS(id), 0); + PS(id) = NULL; PS(id) = PS(mod)->s_create_sid(&PS(mod_data)); if (!PS(id)) { PS(mod)->s_close(&PS(mod_data)); diff --git a/ext/session/tests/user_session_module/gh23043.phpt b/ext/session/tests/user_session_module/gh23043.phpt new file mode 100644 index 000000000000..e3528884a79a --- /dev/null +++ b/ext/session/tests/user_session_module/gh23043.phpt @@ -0,0 +1,35 @@ +--TEST-- +GH-23043 (broken session id code can cause zend_mm_heap corrupted) +--EXTENSIONS-- +session +--CREDITS-- +lmaltsis +--FILE-- + +--EXPECTF-- +string(0) "" + +Warning: SessionHandler::write(): Session ID is too long or contains illegal characters. Only the A-Z, a-z, 0-9, "-", and "," characters are allowed in %s on line %d + +Warning: session_write_close(): Failed to write session data using user defined save handler. (session.save_path: , handler: a::write) in %s on line %d +string(0) "" + +Warning: SessionHandler::write(): Session ID is too long or contains illegal characters. Only the A-Z, a-z, 0-9, "-", and "," characters are allowed in Unknown on line 0 + +Warning: session_write_close(): Failed to write session data using user defined save handler. (session.save_path: , handler: a::write) in Unknown on line 0 diff --git a/ext/simplexml/simplexml.c b/ext/simplexml/simplexml.c index 8cf8e657e58f..4ae396b3fe1d 100644 --- a/ext/simplexml/simplexml.c +++ b/ext/simplexml/simplexml.c @@ -2334,6 +2334,11 @@ PHP_METHOD(SimpleXMLElement, __construct) RETURN_THROWS(); } + if (is_url && CHECK_NULL_PATH(data, data_len)) { + zend_argument_value_error(1, "must not contain any null bytes"); + RETURN_THROWS(); + } + PHP_LIBXML_SANITIZE_GLOBALS(read_file_or_memory); docp = is_url ? xmlReadFile(data, NULL, (int)options) : xmlReadMemory(data, (int)data_len, NULL, NULL, (int)options); PHP_LIBXML_RESTORE_GLOBALS(read_file_or_memory); diff --git a/ext/simplexml/tests/bug_sxe_ctor_nul_path.phpt b/ext/simplexml/tests/bug_sxe_ctor_nul_path.phpt new file mode 100644 index 000000000000..aea5396eac30 --- /dev/null +++ b/ext/simplexml/tests/bug_sxe_ctor_nul_path.phpt @@ -0,0 +1,26 @@ +--TEST-- +SimpleXMLElement constructor rejects embedded NUL in URL/path mode +--EXTENSIONS-- +simplexml +--FILE-- +'); +$path = $tmp . "\0evil"; +try { + new SimpleXMLElement($path, 0, true); + echo "ctor: loaded\n"; +} catch (Throwable $e) { + echo $e::class, ": ", $e->getMessage(), "\n"; +} +try { + simplexml_load_file($path); + echo "load_file: loaded\n"; +} catch (Throwable $e) { + echo $e::class, ": ", $e->getMessage(), "\n"; +} +unlink($tmp); +?> +--EXPECT-- +ValueError: SimpleXMLElement::__construct(): Argument #1 ($data) must not contain any null bytes +ValueError: simplexml_load_file(): Argument #1 ($filename) must not contain any null bytes diff --git a/ext/standard/tests/mail/bug80751.phpt b/ext/standard/tests/mail/bug80751.phpt index b6dc29e42f14..802bd542482d 100644 --- a/ext/standard/tests/mail/bug80751.phpt +++ b/ext/standard/tests/mail/bug80751.phpt @@ -48,7 +48,7 @@ foreach (['to' => $to, 'cc' => $cc, 'bcc' => $bcc] as $recipient => $mailAddress echo "Found the email. {$recipient} received.\n"; } - if ($mail->getHeader('Return-Path') === $from) { + if ($mail->getHeader('Return-Path') === "<{$from}>") { echo "Return-Path is as expected.\n"; }