Req #64439 [Com]: \0 causes error_log strings to be truncated

From: Date: Sun, 04 Sep 2016 14:22:33 +0000
Subject: Req #64439 [Com]: \0 causes error_log strings to be truncated
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-203784@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=64439&edit=1 ID: 64439 Comment by: yonelceruto at gmail dot com Reported by: eric at wepay dot com Summary: \0 causes error_log strings to be truncated Status: Open Type: Feature/Change Request Package: *General Issues Operating System: CentOS PHP Version: 5.4.13 Block user comment: N Private report: N New Comment: I've faced with this issue too, so my question is: Why "\0" character is dumped when private or protected properties are serialized ? It is needed for unserialize process? Previous Comments: ------------------------------------------------------------------------ [2013-11-01 06:34:39] yohgaki@php.net Thanks for the info, but I knew this kind of attack can be done. Anyway, even if we made logging binary safe, there would be other problems. We cannot simply escape special chars because it may broke log analyzers. It's possible escape special chars, but it would not happen in released version. There is developer working on this issue. Changed bug type. ------------------------------------------------------------------------ [2013-10-30 00:42:10] spam2 at rhsoft dot net this is also *security relevant* simply strip or escape control chars and you are done study the mod_security code, they know how to escape log lines http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-1862 ------------------------------------------------------------------------ [2013-10-24 05:30:10] yohgaki@php.net Automatic comment from SVN on behalf of yohgaki Revision: http://svn.php.net/viewvc/?view=revision&revision=331939 Log: Fixed Doc Bug #64439 \0 causes error_log strings to be truncated ------------------------------------------------------------------------ [2013-10-24 05:28:11] yohgaki@php.net This should be documented. ------------------------------------------------------------------------ [2013-03-19 11:41:45] laruence@php.net hmm, yes, error_log is not binary safe. and fix that need a huge work, all sapi's log message need to be updated. and also send mail, log to file related apis a workaround could be done at user side. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=64439 -- Edit this bug report at https://bugs.php.net/bug.php?id=64439&edit=1

« previous php.bugs (#203784) next »