Bug #68535 [NEW]: Uploaded files are not deleted because of missing impersonation
| From: | lf at evasys dot de | Date: | Mon, 01 Dec 2014 23:00:35 +0000 |
| Subject: | Bug #68535 [NEW]: Uploaded files are not deleted because of missing impersonation | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-188877@lists.php.net to get a copy of this message | ||
From: lf at evasys dot de
Operating system: Windows Server 2012
PHP version: 5.5.19
Package: IIS related
Bug Type: Bug
Bug description:Uploaded files are not deleted because of missing impersonation
Description:
------------
When uploading a file by a HTML form to a PHP script, the uploaded file
will remain in upload_tmp_dir, even when the request ended (and this
file was not removed explicitly by the PHP code).
Test script:
---------------
Any file upload from a multipart HTML form.
Expected result:
----------------
Unused, not moved or not deleted temp files of a file upload are
normally deleted by PHP when the request ended. We can reproduce this on
Apache environments. This is also the behavior php.net describes for
file uploads: "The file will be deleted from the temporary directory at
the end of the request if it has not been moved away or renamed.", see:
http://php.net/manual/en/features.file-upload.post-method.php
We can also see in procmon that php.cgi.exe tries to delete the temp
file.
Actual result:
--------------
The file is created in upload_tmp_dir. In our case with the IUSR account
since we use "Anonymous Authentication" in IIS. The file is not touched
by the PHP code. The request ends. PHP tries to delete the temporary
file, but the access is denied.
We analyzed this with procmon. What you can see there is, that
php-cgi.exe process seems not impersonate on the delete request like on
move_uploaded_file() or any other filesystem access.
Workaround: If we add MODIFY rights for IIS_IUSRS group on
uploaded_tmp_dir the file will be deleted after the request ended as
expected.
Environment: PHP 5.3.x/5.4.x via FCGI on IIS 7.x
Reproduced on WS2012, WS2008 R2.
This may also be a security releated issue, because when PHP does not
delete temp files created by uploads the server is vulnerable by a
possible DoS attack.
Maybe related to https://bugs.php.net/bug.php?id=54951
--
Edit bug report at https://bugs.php.net/bug.php?id=68535&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=68535&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=68535&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=68535&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=68535&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=68535&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=68535&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=68535&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=68535&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=68535&r=support
Expected behavior: https://bugs.php.net/fix.php?id=68535&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=68535&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=68535&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=68535&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=68535&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=68535&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=68535&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=68535&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=68535&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=68535&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=68535&r=mysqlcfg