#18863 [NEW]: PHP leaves a SYSV semaphore unclosed (php -v). Denial of service possibility.
| From: | bryce at redhat dot com | Date: | Mon, 12 Aug 2002 04:34:50 +0000 |
| Subject: | #18863 [NEW]: PHP leaves a SYSV semaphore unclosed (php -v). Denial of service possibility. | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-16523@lists.php.net to get a copy of this message | ||
From: bryce@redhat.com
Operating system: RHAT Linux (i386 and Alpha)
PHP version: 4.1.2
PHP Bug Type: Session related
Bug description: PHP leaves a SYSV semaphore unclosed (php -v). Denial of service possibility.
I've been contacted by a php user in the wild who told me that by simply
issuing 'php -v', a semaphore that php opens for session management is not
closed on exit.
This becomes bad news because the ipc system on linux is a global resource
and not based per user, so it's possible for a local user to DOS the box
by running php -v repeatidly.
[test@alpha3 test]$ ipcs > l
[test@alpha3 test]$ php -v
Content-type: text/html
4.1.2
[test@alpha3 test]$ ipcs > ll
[test@alpha3 test]$ diff l ll
9a10,11
> 0x00000000 65538 test 600 1
> 0x00000000 98307 test 600 1
I tried to trace this out between 4.1.2 and 4.2.2 (4.2.2 does not exhibit
this behaviour) but I can find no obvious differances in the codepaths
between versions. This behaviour seems to be present all the way back to
4.0.6 from the little additional checking I made.
Please see
http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=71097
For a more detailed analysis
The RH 4.1.2 configure incantation:
./configure --prefix=/usr --with-config-file-path=/etc
--enable-force-cgi-redirect --disable-debug --enable-pic --disable-rpath
--enable-inline-optimization --with-bz2 --with-db3 --with-curl
--with-dom=/usr --with-exec-dir=/usr/bin --with-freetype-dir=/usr
--with-png-dir=/usr --with-gd --enable-gd-native-ttf --with-ttf
--with-gdbm --with-gettext --with-ncurses --with-gmp --with-iconv
--with-jpeg-dir=/usr --with-mm --with-openssl --with-png --with-pspell
--with-regex=system --with-xml --with-expat-dir=/usr --with-zlib
--with-layout=GNU --enable-bcmath --enable-debugger --enable-exif
--enable-ftp --enable-magic-quotes --enable-safe-mode --enable-sockets
--enable-sysvsem --enable-sysvshm --enable-discard-path
--enable-track-vars --enable-trans-sid --enable-yp --enable-wddx
--without-oci8 --with-imap=shared --with-imap-ssl
--with-kerberos=/usr/kerberos --with-ldap=shared --with-mysql=shared,/usr
--with-pgsql=shared --with-snmp=shared,/usr --with-snmp=shared
--enable-ucd-snmp-hack --with-unixODBC=shared --enable-memory-limit
--enable-bcmath --enable-shmop --enable-versioning --enable-calendar
--enable-dbx --enable-dio --enable-mbstring --enable-mbstr-enc-trans
--enable-force-cgi-redirect
Phil
=--=
--
Edit bug report at http://bugs.php.net/?id=18863&edit=1
--
Fixed in CVS: http://bugs.php.net/fix.php?id=18863&r=fixedcvs
Fixed in release: http://bugs.php.net/fix.php?id=18863&r=alreadyfixed
Need backtrace: http://bugs.php.net/fix.php?id=18863&r=needtrace
Try newer version: http://bugs.php.net/fix.php?id=18863&r=oldversion
Not developer issue: http://bugs.php.net/fix.php?id=18863&r=support
Expected behavior: http://bugs.php.net/fix.php?id=18863&r=notwrong
Not enough info: http://bugs.php.net/fix.php?id=18863&r=notenoughinfo
Submitted twice: http://bugs.php.net/fix.php?id=18863&r=submittedtwice
register_globals: http://bugs.php.net/fix.php?id=18863&r=globals