Req #64439 [Com]: \0 causes error_log strings to be truncated
| From: | yonelceruto at gmail dot com | Date: | Sun, 04 Sep 2016 14:22:33 +0000 |
| Subject: | Req #64439 [Com]: \0 causes error_log strings to be truncated | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-203784@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=64439&edit=1
ID: 64439
Comment by: yonelceruto at gmail dot com
Reported by: eric at wepay dot com
Summary: \0 causes error_log strings to be truncated
Status: Open
Type: Feature/Change Request
Package: *General Issues
Operating System: CentOS
PHP Version: 5.4.13
Block user comment: N
Private report: N
New Comment:
I've faced with this issue too, so my question is: Why "\0" character is dumped when
private or protected properties are serialized ? It is needed for unserialize process?
Previous Comments:
------------------------------------------------------------------------
[2013-11-01 06:34:39] yohgaki@php.net
Thanks for the info, but I knew this kind of attack can be done.
Anyway, even if we made logging binary safe, there would be other problems. We cannot simply escape
special chars because it may broke log analyzers. It's possible escape special chars, but it
would not happen in released version.
There is developer working on this issue. Changed bug type.
------------------------------------------------------------------------
[2013-10-30 00:42:10] spam2 at rhsoft dot net
this is also *security relevant*
simply strip or escape control chars and you are done
study the mod_security code, they know how to escape log lines
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-1862
------------------------------------------------------------------------
[2013-10-24 05:30:10] yohgaki@php.net
Automatic comment from SVN on behalf of yohgaki
Revision: http://svn.php.net/viewvc/?view=revision&revision=331939
Log: Fixed Doc Bug #64439 \0 causes error_log strings to be truncated
------------------------------------------------------------------------
[2013-10-24 05:28:11] yohgaki@php.net
This should be documented.
------------------------------------------------------------------------
[2013-03-19 11:41:45] laruence@php.net
hmm, yes, error_log is not binary safe.
and fix that need a huge work, all sapi's log message need to be updated. and also
send mail, log to file related apis
a workaround could be done at user side.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=64439
--
Edit this bug report at https://bugs.php.net/bug.php?id=64439&edit=1