Req #68424 [NEW]: Add new PDO mysql connection attr to control multi statements option
| From: | peter dot wolanin at acquia dot com | Date: | Fri, 14 Nov 2014 15:02:30 +0000 |
| Subject: | Req #68424 [NEW]: Add new PDO mysql connection attr to control multi statements option | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-188604@lists.php.net to get a copy of this message | ||
From: peter dot wolanin at acquia dot com
Operating system: all
PHP version: 5.6.3
Package: PDO MySQL
Bug Type: Feature/Change Request
Bug description:Add new PDO mysql connection attr to control multi statements option
Description:
------------
Proposed fix: https://github.com/php/php-src/pull/896
mysqli does not set the CLIENT_MULTI_STATEMENTS flag on connect, so a
query with multiple statements fails.
For PDO mysql, it hard-codes the CLIENT_MULTI_STATEMENTS flag in the
connection, so there is no way to disable it. However, if using native
prepares, sending multiple statements fails on the server. This is
inconsistent.
This PR adds a new MySQL-specific attribute that can be only set at
connection time to explicitly enable or disable multi statements. As
written, it leaves the default the same as current master (enabled).
While this PR is against master, I think this change falls somewhere
between a feature and a bugfix and should be back-ported to all
supported versions.
The motivation for this is the severity of the recent SQL injection
vulnerability in Drupal. If we had any way to disable multi statement in
PDO (which is used in Drupal 7.x but not 6.x), we would have, and the
vulnerability would have been significantly mitigated. see:
https://www.drupal.org/SA-CORE-2014-005
Test script:
---------------
https://github.com/php/php-src/pull/896
includes added test.
Expected result:
----------------
It should be possible to limit PDO MySQL to single statement execution
so it behaves like mysqli
Actual result:
--------------
multi-statement option is hard-coded into the connection logic
--
Edit bug report at https://bugs.php.net/bug.php?id=68424&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=68424&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=68424&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=68424&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=68424&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=68424&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=68424&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=68424&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=68424&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=68424&r=support
Expected behavior: https://bugs.php.net/fix.php?id=68424&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=68424&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=68424&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=68424&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=68424&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=68424&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=68424&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=68424&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=68424&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=68424&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=68424&r=mysqlcfg