Bug #73922 [Csd]: Missing null byte checks for paths in curlfile_ctor()

From: Date: Mon, 16 Jan 2017 07:03:48 +0000
Subject: Bug #73922 [Csd]: Missing null byte checks for paths in curlfile_ctor()
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-206653@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73922&edit=1 ID: 73922 User updated by: max at cert dot cx Reported by: max at cert dot cx Summary: Missing null byte checks for paths in curlfile_ctor() Status: Closed Type: Bug Package: cURL related Operating System: BSD PHP Version: 5.6.29 Assigned To: stas Block user comment: N Private report: N New Comment: in your opinion it is a security flaw? If not, what is the difference between CVE-2015-4598, CVE-2015-3412, CVE-2015-3411 and this vulnerability? Previous Comments: ------------------------------------------------------------------------ [2017-01-16 01:35:11] stas@php.net The fix for this bug has been committed. Snapshots of the sources are packaged every three hours; this change will be in the next snapshot. You can grab the snapshot at http://snaps.php.net/. For Windows: http://windows.php.net/snapshots/ Thank you for the report, and for helping us make PHP better. ------------------------------------------------------------------------ [2017-01-12 18:16:00] max at cert dot cx Description: ------------ Missing null byte checks for paths in curlfile_ctor() curl_file_create() doesn’t ensure that pathnames lack NULL byte, which might allow attacker to manipulate the upload file name and path. Affected code: ================================== static void curlfile_ctor(INTERNAL_FUNCTION_PARAMETERS) { char *fname = NULL, *mime = NULL, *postname = NULL; size_t fname_len, mime_len, postname_len; zval *cf = return_value; if (zend_parse_parameters(ZEND_NUM_ARGS(), "s|ss", &fname, &fname_len, &mime, &mime_len, &postname, &postname_len) == FAILURE) { ⇐==== return; } ================================== Affected function: ================================== CURLFile curl_file_create ( string $filename [, string $mimetype [, string $postname ]] ) ================================== type of parameters filename to change. From a security perspective, You may consider changing the type of parameter postname Best, Maksymilian Arciemowicz Test script: --------------- <?php $request = curl_init('http://127.0.0.1/print.php'); curl_setopt($request, CURLOPT_POST, true); $args['file'] = curl_file_create("./test.test\0.file.to.send.png", "image/png", "test.test\0.file.to.send.png"); curl_setopt($request, CURLOPT_POSTFIELDS, $args); echo curl_exec($request); curl_close($request); Expected result: ---------------- warning Actual result: -------------- uploaded test.test and name Array ( [file] => Array ( [name] => test.test ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=73922&edit=1

« previous php.bugs (#206653) next »