Bug #73910 [Csd]: Missing null byte checks for paths in ZipArchive::extractTo
| From: | max at cert dot cx | Date: | Mon, 16 Jan 2017 07:05:33 +0000 |
| Subject: | Bug #73910 [Csd]: Missing null byte checks for paths in ZipArchive::extractTo | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-206654@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=73910&edit=1
ID: 73910
User updated by: max at cert dot cx
Reported by: max at cert dot cx
Summary: Missing null byte checks for paths in
ZipArchive::extractTo
Status: Closed
Type: Bug
Package: Zip Related
Operating System: *
PHP Version: 5.6.29
Assigned To: stas
Block user comment: N
Private report: N
New Comment:
in your opinion it is a security flaw? If not, what is the difference between CVE-2015-4598,
CVE-2015-3412, CVE-2015-3411 and this vulnerability?
Previous Comments:
------------------------------------------------------------------------
[2017-01-16 01:36:24] stas@php.net
The fix for this bug has been committed.
Snapshots of the sources are packaged every three hours; this change
will be in the next snapshot. You can grab the snapshot at
http://snaps.php.net/.
For Windows:
http://windows.php.net/snapshots/
Thank you for the report, and for helping us make PHP better.
------------------------------------------------------------------------
[2017-01-12 01:05:47] cmb@php.net
The following patch has been added/updated:
Patch Name: fix-73910
Revision: 1484183147
URL: https://bugs.php.net/patch-display.php?bug=73910&patch=fix-73910&revision=1484183147
------------------------------------------------------------------------
[2017-01-10 20:32:04] max at cert dot cx
Description:
------------
ZipArchive->extractTo() doesnât ensure that pathnames lack NULL byte, which might allow
attacker to manipulate the directory path.
Affected method:
------------------------------------------
static ZIPARCHIVE_METHOD(extractTo)
{
struct zip *intern;
zval *self = getThis();
zval *zval_files = NULL;
zval *zval_file = NULL;
php_stream_statbuf ssb
;..
if (!self) {
RETURN_FALSE;
}
if (zend_parse_parameters(ZEND_NUM_ARGS(), "s|z", &pathto, &pathto_len,
&zval_files) == FAILURE) {
return;
}
if (pathto_len < 1) {
RETURN_FALSE;
}
------------------------------------------
Test script:
---------------
<?php
if(file_exists("LEVELA/EXTRACTED__HERE")) echo "LEVELA/EXTRACTED__HERE
EXISTS!!!1\n";
if(file_exists("LEVELA/LEVELB/EXTRACTED__HERE")) echo "LEVELB/EXTRACTED__HERE
EXISTS!!!2\n";
$zip = new ZipArchive;
if ($zip->open('toPack/EXTRACTED__HERE.zip') === TRUE) {
$zip->extractTo("./LEVELA/\0LEVELB");
$zip->close();
echo "ok\n";
} else {
echo "failed\n";
}
if(file_exists("LEVELA/EXTRACTED__HERE")) echo "LEVELA/EXTRACTED__HERE
EXISTS!!!3\n";
if(file_exists("LEVELA/LEVELB/EXTRACTED__HERE")) echo "LEVELB/EXTRACTED__HERE
EXISTS!!!4\n";
?>
Expected result:
----------------
expected parameter not string
Actual result:
--------------
# php zip.php
ok
LEVELA/EXTRACTED__HERE EXISTS!!!3
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=73910&edit=1