Edit report at https://bugs.php.net/bug.php?id=67481&edit=1
ID: 67481
Comment by: spam at rw23 dot de
Reported by: Danack at basereality dot com
Summary: Opcache uses wrong file from cache
Status: Open
Type: Bug
Package: opcache
Operating System: Centos
PHP Version: 5.5.13
Block user comment: N
Private report: N
New Comment:
This is also a big security issue for two reasons:
1. it allows to read files from other chroots (containing secrets)
if you know another chroot vhost (project1) is running a wordpress installation, you can create a
file with a path existing on project1 like /web/wp-config.php in project2, include it from project2
and then echo DB_PASSWORD, DB_HOST and so on. you can read the secrets from project1.
2. i have not tried it, but i think it allows to override files on other chroots and inject
arbitrary code.
you can create a /web/index.php containing a php backdoor. if the opcache for that file gets cleared
(server restart, garbage collection) and your file is the first loaded into cache again, you have
your code executed in other chroots.
a user running chroots without overlapping files will not notice this problem, bringing this
vulnerability into production enviroments.
Previous Comments:
------------------------------------------------------------------------
[2014-09-10 06:19:59] spam at rw23 dot de
php version is 5.5.16 for me
------------------------------------------------------------------------
[2014-09-10 06:16:06] spam at rw23 dot de
its a common problem and also a deal-breaker when using chrooted enviroments like the php-fpm setup,
you can find many complains on the net:
https://www.google.com/search?q=php-fpm+chroot+opcache.so
by using a config file from a wrong neighbor project, this bug can even break things.
this is not happening with APC or xcache, so these work around the problem somehow.
------------------------------------------------------------------------
[2014-08-09 03:59:32] wojjie at gmail dot com
Same problem exists if you are in a chroot environment. Consider the example provided by the
original author and add chroot to the project directories.
ie:
/home/project1/
/home/project2/
Now each site's index.php is actually:
/web/index.php (project1)
/web/index.php (project2)
Somehow this also causes a collision in the cache and causes PHP to serve the wrong index.php from
cache if you hit project1 first followed by project2 next.
------------------------------------------------------------------------
[2014-06-19 17:43:18] Danack at basereality dot com
Made summary not be one word.
------------------------------------------------------------------------
[2014-06-19 16:02:37] Danack at basereality dot com
Description:
------------
When the config 'opcache.validate_timestamps' is set to 0 opcache incorrectly resolves
relative filenames.
If you include a file with require "../src/bootstrap.php"; from two
completely different directories then OPcache will serve the same file even though
realpath("../src/bootstrap.php"); resolves to completely different
directories.
This does not happen when opcache.validate_timestamps is set to a non-zero value.
It can also be worked around by using require __DIR__ .
'/../src/bootstrap.php';
Test script:
---------------
File /home/project1/web/index.php
=================================
<?php
require "../src/bootstrap.php";
?>
File /home/project2/web/index.php
=================================
<?php
require "../src/bootstrap.php";
?>
File /home/project2/src/bootstrap.php
=====================================
<?php
echo "I am project2's bootstrap file.";
If you go to a webpage served by project1 first, then go to a webpage served by project2, project2
will get be given project1's bootstrap file.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=67481&edit=1