Bug #68851 [Opn]: PHP and Apache2 interpret duplicate Authentication headers differently

From: Date: Sun, 18 Jan 2015 13:08:16 +0000
Subject: Bug #68851 [Opn]: PHP and Apache2 interpret duplicate Authentication headers differently
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-190039@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68851&edit=1 ID: 68851 Updated by: requinix@php.net Reported by: phillip dot berndt at googlemail dot com Summary: PHP and Apache2 interpret duplicate Authentication headers differently Status: Open Type: Bug Package: Apache2 related PHP Version: 5.4.36 Block user comment: N Private report: N New Comment: Multiple Authorization headers aren't actually permitted by the RFCs. What you're sending is equivalent to Authorization: Basic dXNlcjp1c2Vy, Basic YWRtaW46YWRtaW4 Base-64 ignores whitespace and other invalid characters so that gets treated like Authorization: Basic dXNlcjp1c2VyBasicYWRtaW46YWRtaW4 which decodes to ("user:" followed by) the crazy stuff you're seeing. echo urlencode(base64_decode('dXNlcjp1c2VyBasicYWRtaW46YWRtaW4')); // user%3Auser%05%AB%22q%85%91%B5%A5%B8%E9%85%91%B5%A5%B8 IMO since this situation is prohibited, PHP's behavior is acceptable. Apache ignoring the additional headers is reasonable because multiple Authorizations don't make sense, and PHP combining them is not unreasonable because multiple headers means necessarily that they are equivalent to one which has the values combined and comma-separated. Previous Comments: ------------------------------------------------------------------------ [2015-01-18 12:26:48] phillip dot berndt at googlemail dot com Description: ------------ If a request contains multiple Authorization headers, PHP and Apache parse them differently. If Apache does the authorization, this leads to PHP having a wrong password in $_SERVER[PHP_AUTH_PW]: Apache uses the first header for authentication. PHP concatenates both headers somehow, I suppose with the usual ", " in between, and then messes up base64 decoding (the source code seems to actually call uudecode()?!). This alone does not have any security implications I can think of, therefore I'll categorize this as a simple bug. I haven't looked into the cause of the bug in the base64 decoder though. Test script: --------------- htaccess file: AuthType Basic AuthUserFile /path/to/htpasswd AuthName "test" Require valid-user php script: <?php header("Content-type: text/plain"); echo urlencode($_SERVER["PHP_AUTH_PW"]); htpasswd allows login for user:user Expected result: ---------------- $ curl "http://path/to/page" -H "Authorization: Basic dXNlcjp1c2Vy" -H "Authorization: Basic YWRtaW46YWRtaW4=" user Actual result: -------------- $ curl "http://path/to/page" -H "Authorization: Basic dXNlcjp1c2Vy" -H "Authorization: Basic YWRtaW46YWRtaW4=" user%05%AB%22q%85%91%B5%A5%B8%E9%85%91%B5%A5%B8% ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=68851&edit=1

« previous php.bugs (#190039) next »