Bug #66724 [Com]: ldap_get_entries does not escape DN values on Active Directory

From: Date: Fri, 27 Jan 2017 17:44:14 +0000
Subject: Bug #66724 [Com]: ldap_get_entries does not escape DN values on Active Directory
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-206980@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=66724&edit=1

 ID:                 66724
 Comment by:         post at rolandgruber dot de
 Reported by:        post at rolandgruber dot de
 Summary:            ldap_get_entries does not escape DN values on Active
                     Directory
 Status:             Assigned
 Type:               Bug
 Package:            LDAP related
 Operating System:   Debian Linux
 PHP Version:        5.4.25
 Assigned To:        heiglandreas
 Block user comment: N
 Private report:     N

 New Comment:

True, on PHP 7 it is "ou=foo\2C bar,ou=test,o=test,c=de" for OpenLDAP.


Previous Comments:
------------------------------------------------------------------------
[2017-01-22 15:22:01] heiglandreas@php.net

The DN should contain EITHER '\,' OR '\2C' but NOT '\5C\2C'. IMO that
means that the value in the CN-Attribute already contains '\,' and not a simple
','. Can you please check that? 

Additionally I checked that against a third LDAP-Server:

$ldap = ldap_connect('ldap://pksldap.tttc.de');
ldap_bind($ldap);
$result = ldap_search($ldap, 'c=DE', 'sn=Jahneke');
$res = ldap_get_entries($ldap, $result);
var_Dump($res[0]['dn']);
//string(101) "cn=Jahneke\2C Ralf- ChristophSER:799945522,ou=T-TeleSec SigG Test CA
15:PN,o=Deutsche Telekom AG,c=de"
var_Dump($res[0]['cn'][0]);
string(37) "Jahneke, Ralf- ChristophSER:799945522"

Could you run that agains your OpenLDAP and ActiveDirectory (with appropriately adapted
search-filter)? Thanks!

------------------------------------------------------------------------
[2017-01-22 15:21:58] heiglandreas@php.net

The DN should contain EITHER '\,' OR '\2C' but NOT '\5C\2C'. IMO that
means that the value in the CN-Attribute already contains '\,' and not a simple
','. Can you please check that? 

Additionally I checked that against a third LDAP-Server:

$ldap = ldap_connect('ldap://pksldap.tttc.de');
ldap_bind($ldap);
$result = ldap_search($ldap, 'c=DE', 'sn=Jahneke');
$res = ldap_get_entries($ldap, $result);
var_Dump($res[0]['dn']);
//string(101) "cn=Jahneke\2C Ralf- ChristophSER:799945522,ou=T-TeleSec SigG Test CA
15:PN,o=Deutsche Telekom AG,c=de"
var_Dump($res[0]['cn'][0]);
string(37) "Jahneke, Ralf- ChristophSER:799945522"

Could you run that agains your OpenLDAP and ActiveDirectory (with appropriately adapted
search-filter)? Thanks!

------------------------------------------------------------------------
[2017-01-22 08:53:35] post at rolandgruber dot de

I verified with PHP 7.0.12 against Windows 2012 and OpenLDAP 2.4.40

------------------------------------------------------------------------
[2017-01-22 04:22:45] php-bugs at lists dot php dot net

No feedback was provided. The bug is being suspended because
we assume that you are no longer experiencing the problem.
If this is not the case and you are able to provide the
information that was requested earlier, please do so and
change the status of the bug back to "Re-Opened". Thank you.

------------------------------------------------------------------------
[2017-01-11 19:28:42] post at rolandgruber dot de

Verified with PHP 7.0.12 against Windows 2012 and OpenLDAP 2.4.40

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=66724


--
Edit this bug report at https://bugs.php.net/bug.php?id=66724&edit=1


Thread (12 messages)

« previous php.bugs (#206980) next »