Req #68599 [Opn]: exec()/passthru() function should use execv, execve

From: Date: Thu, 22 Jan 2015 22:03:46 +0000
Subject: Req #68599 [Opn]: exec()/passthru() function should use execv, execve
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-190155@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68599&edit=1 ID: 68599 Updated by: yohgaki@php.net Reported by: yohgaki@php.net Summary: exec()/passthru() function should use execv, execve Status: Open Type: Feature/Change Request Package: Program Execution Operating System: ANY PHP Version: Irrelevant -Assigned To: +Assigned To: yohgaki Block user comment: N Private report: Y New Comment: Stas, it's not direct security issue since user may execute commands safely with exec. However, writing secure command with arguments is not trivial work as it seems. execv, execve is much easier/safer than exec. It would be only master improvement. (It's security improvement, IMHO) If no one objects, I'll write patch. Things that I'm not sure is why pcntl is enabled only in CLI. It's because signal handling I suppose. Is there any other reasons? Previous Comments: ------------------------------------------------------------------------ [2014-12-30 08:29:52] stas@php.net Not sure why is it a security issue? ------------------------------------------------------------------------ [2014-12-12 23:02:22] yohgaki@php.net Description: ------------ I suppose pcntl module is not available because of signal handling. https://bugs.php.net/bug.php?id=50116 Since exec() is using exec system call, exec() is extremely vulnerable to mistakes. Change string exec ( string $command [, array &$output [, int &$return_var ]] ) void passthru ( string $command [, int &$return_var ] ) to string exec ( string $command [, array &$output [, int &$return_var [, $args [, $env]]]] ) void passthru ( string $command [, int &$return_var [, $args [, $env]]] ) Use evecv if $args is passed, use execve if $env is passed. Any comments? Especially for windows? ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=68599&edit=1

« previous php.bugs (#190155) next »