Bug #73922 [Csd]: Missing null byte checks for paths in curlfile_ctor()
| From: | max at cert dot cx | Date: | Mon, 16 Jan 2017 07:03:48 +0000 |
| Subject: | Bug #73922 [Csd]: Missing null byte checks for paths in curlfile_ctor() | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-206653@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=73922&edit=1
ID: 73922
User updated by: max at cert dot cx
Reported by: max at cert dot cx
Summary: Missing null byte checks for paths in
curlfile_ctor()
Status: Closed
Type: Bug
Package: cURL related
Operating System: BSD
PHP Version: 5.6.29
Assigned To: stas
Block user comment: N
Private report: N
New Comment:
in your opinion it is a security flaw? If not, what is the difference between CVE-2015-4598,
CVE-2015-3412, CVE-2015-3411 and this vulnerability?
Previous Comments:
------------------------------------------------------------------------
[2017-01-16 01:35:11] stas@php.net
The fix for this bug has been committed.
Snapshots of the sources are packaged every three hours; this change
will be in the next snapshot. You can grab the snapshot at
http://snaps.php.net/.
For Windows:
http://windows.php.net/snapshots/
Thank you for the report, and for helping us make PHP better.
------------------------------------------------------------------------
[2017-01-12 18:16:00] max at cert dot cx
Description:
------------
Missing null byte checks for paths in curlfile_ctor()
curl_file_create() doesnât ensure that pathnames lack NULL byte, which might allow attacker to
manipulate the upload file name and path.
Affected code:
==================================
static void curlfile_ctor(INTERNAL_FUNCTION_PARAMETERS)
{
char *fname = NULL, *mime = NULL, *postname = NULL;
size_t fname_len, mime_len, postname_len;
zval *cf = return_value;
if (zend_parse_parameters(ZEND_NUM_ARGS(), "s|ss", &fname, &fname_len,
&mime, &mime_len, &postname, &postname_len) == FAILURE) { â====
return;
}
==================================
Affected function:
==================================
CURLFile curl_file_create ( string $filename [, string $mimetype [, string $postname ]] )
==================================
type of parameters filename to change. From a security perspective, You may consider changing the
type of parameter postname
Best,
Maksymilian Arciemowicz
Test script:
---------------
<?php
$request = curl_init('http://127.0.0.1/print.php');
curl_setopt($request, CURLOPT_POST, true);
$args['file'] = curl_file_create("./test.test\0.file.to.send.png",
"image/png", "test.test\0.file.to.send.png");
curl_setopt($request, CURLOPT_POSTFIELDS, $args);
echo curl_exec($request);
curl_close($request);
Expected result:
----------------
warning
Actual result:
--------------
uploaded test.test and name
Array
(
[file] => Array
(
[name] => test.test
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=73922&edit=1