Bug #74860 [Com]: Uncaught exceptions not being formatted properly when error_log set to "syslog"

From: Date: Fri, 04 Aug 2017 12:19:27 +0000
Subject: Bug #74860 [Com]: Uncaught exceptions not being formatted properly when error_log set to "syslog"
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-210476@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=74860&edit=1 ID: 74860 Comment by: spam2 at rhsoft dot net Reported by: philipp at redfish-solutions dot com Summary: Uncaught exceptions not being formatted properly when error_log set to "syslog" Status: Open Type: Bug Package: Output Control Operating System: linux 4.9.30 PHP Version: 7.1.6 Block user comment: N Private report: N New Comment: and error_log() should also take care of non-printable characters because otherwise it's possible to trigger logfiles with control chars and that can lead in "cat logifle" unexpected executes code from untrusted input part of the logging Previous Comments: ------------------------------------------------------------------------ [2017-08-04 11:54:03] krakjoe@php.net The fix is in the wrong place. The fix should be to modify the php_syslog function to conform with expectations. I believe a more robust fix would be preferable ... ------------------------------------------------------------------------ [2017-07-26 16:35:11] philipp at redfish-solutions dot com Can we please get movement on this? There's a fix attached. ------------------------------------------------------------------------ [2017-07-11 04:16:42] philipp at redfish-solutions dot com > yeah, that's how to create security issues as mod_rewrite did in case one did "cat > logfile" leading to execute commands because of not properly filtered control chars Sorry, not familiar with that CVE. What are the details and how does it relate? ------------------------------------------------------------------------ [2017-07-05 23:26:03] spam2 at rhsoft dot net > I don't think there is an overall conses on how to handle this, > the RFC suggests that a receiver has to deal with that if > non-printable (non-allowed) characters are used in the MSG part yeah, that's how to create security issues as mod_rewrite did in case one did "cat logfile" leading to execute commands because of not properly filtered control chars ------------------------------------------------------------------------ [2017-07-05 23:25:22] philipp at redfish-solutions dot com For what it's worth, I'm using syslog-ng 3.9.1 on my system. In the case of using rsyslog, the message would have been reformatted as it was written to disk with newlines being replaced literally with "\012" (i.e. an escaped octal sequence). Also not desirable. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=74860 -- Edit this bug report at https://bugs.php.net/bug.php?id=74860&edit=1

« previous php.bugs (#210476) next »