Bug #68949 [Com]: Very strange binary dump and class not found

From: Date: Wed, 04 Feb 2015 16:48:54 +0000
Subject: Bug #68949 [Com]: Very strange binary dump and class not found
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-190461@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68949&edit=1 ID: 68949 Comment by: phpmpan at mpan dot pl Reported by: yunosh@php.net Summary: Very strange binary dump and class not found Status: Open Type: Bug Package: Scripting Engine problem Operating System: Linux PHP Version: master-Git-2015-01-29 (Git) Block user comment: N Private report: N New Comment: As {[2015-01-30 20:02 UTC] requinix@php.net} has pointed out, nothing is leaked. The dump is just the source code from "TestCase.php" interpreted as UTF-16LE encoded data. No security problem is present. The first sixteen octets are: 3C 3F 70 68 70 0A 2F 2A 2A 0A 20 2A 20 42 61 73 ("<?php\n/**\n * Bas") Upon inclusion PHP reads this as UTF-16LE, interpreting this as eight characters: U+3F3C U+6870 U+0A70 U+2A2F U+0A2A U+2A20 U+4220 U+7361 ("㼼桰ੰ⨯ਪ⨠䈠獡"). Since "㼼桰ੰ⨯ਪ" is, obviously, not a PHP opening tag, PHP treats this not as a code, but as a raw data and sends it as it would with any other data. Since no PHP code is ever found, Horde_Auth_TestCase is never defined by the file and a fatal error occurs, which is also visible in the output. So everything works as expected. Previous Comments: ------------------------------------------------------------------------ [2015-02-02 08:02:11] yunosh@php.net That's correct, the file contains some binary data contained in PHP code (password hashes). We could (and should) fix that of course. But it's still a BC break that this file doesn't parse anymore. And the leaking of what looks like some memory dump could be the sign of a bigger, maybe even security relevant, problem. ------------------------------------------------------------------------ [2015-02-01 05:25:30] phpmpan at mpan dot pl I mean the "TestCase.php" file. ------------------------------------------------------------------------ [2015-02-01 05:18:26] phpmpan at mpan dot pl At byte offset 0x044C there is a sequence (", f, o, o, b, a, r, ") encoded using UTF-16LE, hence containing 0x00 octets. At 0x0639 and 0x067C there is something that looks like binary data embedded directly in the script. ------------------------------------------------------------------------ [2015-01-31 01:49:39] yohgaki@php.net Could you identify when this issue is introduced? ------------------------------------------------------------------------ [2015-01-30 20:02:35] requinix@php.net That output is actually some PHP code (class definition for Horde_Auth_TestCase) being incorrectly interpreted in UTF-16 encoding. Seems like there's something wrong with the TestCase.php file itself as GitHub doesn't want to show the file contents, but some cursory tests against the raw download all show it's fine. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=68949 -- Edit this bug report at https://bugs.php.net/bug.php?id=68949&edit=1

« previous php.bugs (#190461) next »