Bug #68949 [Fbk->Csd]: Very strange binary dump and class not found
| From: | yunosh@php.net | Date: | Mon, 20 Jun 2016 15:17:01 +0000 |
| Subject: | Bug #68949 [Fbk->Csd]: Very strange binary dump and class not found | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-201755@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=68949&edit=1
ID: 68949
Updated by: yunosh@php.net
Reported by: yunosh@php.net
Summary: Very strange binary dump and class not found
-Status: Feedback
+Status: Closed
Type: Bug
Package: Scripting Engine problem
Operating System: Linux
PHP Version: master-Git-2015-01-29 (Git)
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Thank you for your bug report. This issue has already been fixed
in the latest released version of PHP, which you can download at
http://www.php.net/downloads.php
Cannot reproduce anymore, at least with 7.0.4.
Previous Comments:
------------------------------------------------------------------------
[2016-06-20 14:17:07] cmb@php.net
Jan, does this issue still persist with latest PHP 7? If so, the
affected PHP version should be updated, at least.
------------------------------------------------------------------------
[2015-02-04 16:57:55] yunosh@php.net
Still a regression from PHP 5 that should be documented then.
------------------------------------------------------------------------
[2015-02-04 16:48:52] phpmpan at mpan dot pl
As {[2015-01-30 20:02 UTC] requinix@php.net} has pointed out, nothing is leaked. The dump is just
the source code from "TestCase.php" interpreted as UTF-16LE encoded data. No security
problem is present.
The first sixteen octets are:
3C 3F 70 68 70 0A 2F 2A 2A 0A 20 2A 20 42 61 73
("<?php\n/**\n * Bas")
Upon inclusion PHP reads this as UTF-16LE, interpreting this as eight characters: U+3F3C U+6870
U+0A70 U+2A2F U+0A2A U+2A20 U+4220 U+7361
("㼼桰ੰ⨯ਪ⨠ä ç¡"). Since
"㼼桰ੰ⨯ਪ" is, obviously, not a PHP opening tag, PHP treats this not
as a code, but as a raw data and sends it as it would with any other data. Since no PHP code is ever
found,
Horde_Auth_TestCase is never defined by the file and a fatal error occurs, which
is also visible in the output.
So everything works as expected.
------------------------------------------------------------------------
[2015-02-02 08:02:11] yunosh@php.net
That's correct, the file contains some binary data contained in PHP code (password hashes). We
could (and should) fix that of course. But it's still a BC break that this file doesn't
parse anymore. And the leaking of what looks like some memory dump could be the sign of a bigger,
maybe even security relevant, problem.
------------------------------------------------------------------------
[2015-02-01 05:25:30] phpmpan at mpan dot pl
I mean the "TestCase.php" file.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=68949
--
Edit this bug report at https://bugs.php.net/bug.php?id=68949&edit=1