Bug #45132 [Opn->Dup]: escapeshellcmd removes swedish characters

From: Date: Tue, 03 Feb 2015 06:59:49 +0000
Subject: Bug #45132 [Opn->Dup]: escapeshellcmd removes swedish characters
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-190428@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=45132&edit=1

 ID:                 45132
 Updated by:         yohgaki@php.net
 Reported by:        tom at collegit dot se
 Summary:            escapeshellcmd removes swedish characters
-Status:             Open
+Status:             Duplicate
 Type:               Bug
 Package:            Program Execution
 Operating System:   *
 PHP Version:        5.*, 6CVS (2009-05-05)
 Block user comment: N
 Private report:     N

 New Comment:

It removes non-ascii chars. Make this a dup of

https://bugs.php.net/bug.php?id=54391


Previous Comments:
------------------------------------------------------------------------
[2010-05-19 14:23:47] mike@php.net

Works here, but needs to be documented that escapeshell*() functions are locale dependent.

------------------------------------------------------------------------
[2009-05-07 13:52:06] jani@php.net

See also bug #44564 (and can still verify using latest CVS)


------------------------------------------------------------------------
[2008-08-07 06:23:19] tstarling at wikimedia dot org

The issue is that previously 8-bit clean locales, like "C", are now being validated for
whatever character set they supposedly are, with characters above 127 being removed. 

The suggested fix, here and on https://bugzilla.wikimedia.org/show_bug.cgi?id=14944
, appears to reopen whatever security vulnerability it was that the patch fixed in the first place. 


$ LANG=C php eval.php
> setlocale(LC_CTYPE, 'en_US.UTF-8')
> echo escapeshellarg("\xC3\x96")
'Ö'
> passthru('locale')
LANG=C
LC_CTYPE="C"
LC_NUMERIC="C"
LC_TIME="C"
LC_COLLATE="C"
LC_MONETARY="C"
LC_MESSAGES="C"
LC_PAPER="C"
LC_NAME="C"
LC_ADDRESS="C"
LC_TELEPHONE="C"
LC_MEASUREMENT="C"
LC_IDENTIFICATION="C"
LC_ALL=

Because the environment variable LC_CTYPE is not set by setlocale(), the spawned shell sees the old
character set, not the new one. So the shell can be passed an argument escaped for the wrong
character set, potentially opening a vulnerability. 

I'm assuming that the attack scenario for this vulnerability is where an attacker can set
environment variables such as LANG to a vulnerable character set, before starting PHP. Because if an
attacker can set environment variables during execution of a script, the bug is not fixed. But in
that case you're probably screwed anyway.

------------------------------------------------------------------------
[2008-05-29 23:09:34] felipe@php.net

Try using:
setlocale(LC_CTYPE, "UTF8", "en_US.UTF-8");

------------------------------------------------------------------------
[2008-05-29 22:55:58] jani@php.net

Ilia, did that fix get into actual release..?

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=45132


--
Edit this bug report at https://bugs.php.net/bug.php?id=45132&edit=1


Thread (7 messages)

« previous php.bugs (#190428) next »