Sec Bug->Bug #73910 [Ver->Csd]: Missing null byte checks for paths in ZipArchive::extractTo

From: Date: Mon, 16 Jan 2017 01:36:25 +0000
Subject: Sec Bug->Bug #73910 [Ver->Csd]: Missing null byte checks for paths in ZipArchive::extractTo
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-206640@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73910&edit=1 ID: 73910 Updated by: stas@php.net Reported by: max at cert dot cx Summary: Missing null byte checks for paths in ZipArchive::extractTo -Status: Verified +Status: Closed -Type: Security +Type: Bug Package: Zip Related Operating System: * PHP Version: 5.6.29 -Assigned To: +Assigned To: stas Block user comment: N Private report: Y New Comment: The fix for this bug has been committed. Snapshots of the sources are packaged every three hours; this change will be in the next snapshot. You can grab the snapshot at http://snaps.php.net/. For Windows: http://windows.php.net/snapshots/ Thank you for the report, and for helping us make PHP better. Previous Comments: ------------------------------------------------------------------------ [2017-01-12 01:05:47] cmb@php.net The following patch has been added/updated: Patch Name: fix-73910 Revision: 1484183147 URL: https://bugs.php.net/patch-display.php?bug=73910&patch=fix-73910&revision=1484183147 ------------------------------------------------------------------------ [2017-01-10 20:32:04] max at cert dot cx Description: ------------ ZipArchive->extractTo() doesn’t ensure that pathnames lack NULL byte, which might allow attacker to manipulate the directory path. Affected method: ------------------------------------------ static ZIPARCHIVE_METHOD(extractTo) { struct zip *intern; zval *self = getThis(); zval *zval_files = NULL; zval *zval_file = NULL; php_stream_statbuf ssb ;.. if (!self) { RETURN_FALSE; } if (zend_parse_parameters(ZEND_NUM_ARGS(), "s|z", &pathto, &pathto_len, &zval_files) == FAILURE) { return; } if (pathto_len < 1) { RETURN_FALSE; } ------------------------------------------ Test script: --------------- <?php if(file_exists("LEVELA/EXTRACTED__HERE")) echo "LEVELA/EXTRACTED__HERE EXISTS!!!1\n"; if(file_exists("LEVELA/LEVELB/EXTRACTED__HERE")) echo "LEVELB/EXTRACTED__HERE EXISTS!!!2\n"; $zip = new ZipArchive; if ($zip->open('toPack/EXTRACTED__HERE.zip') === TRUE) { $zip->extractTo("./LEVELA/\0LEVELB"); $zip->close(); echo "ok\n"; } else { echo "failed\n"; } if(file_exists("LEVELA/EXTRACTED__HERE")) echo "LEVELA/EXTRACTED__HERE EXISTS!!!3\n"; if(file_exists("LEVELA/LEVELB/EXTRACTED__HERE")) echo "LEVELB/EXTRACTED__HERE EXISTS!!!4\n"; ?> Expected result: ---------------- expected parameter not string Actual result: -------------- # php zip.php ok LEVELA/EXTRACTED__HERE EXISTS!!!3 ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=73910&edit=1

« previous php.bugs (#206640) next »