Bug #74860 [Com]: Uncaught exceptions not being formatted properly when error_log set to "syslog"

From: Date: Fri, 04 Aug 2017 18:54:09 +0000
Subject: Bug #74860 [Com]: Uncaught exceptions not being formatted properly when error_log set to "syslog"
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-210484@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=74860&edit=1

 ID:                 74860
 Comment by:         philipp at redfish-solutions dot com
 Reported by:        philipp at redfish-solutions dot com
 Summary:            Uncaught exceptions not being formatted properly
                     when error_log set to "syslog"
 Status:             Open
 Type:               Bug
 Package:            Output Control
 Operating System:   linux 4.9.30
 PHP Version:        7.1.6
 Block user comment: N
 Private report:     N

 New Comment:

> and error_log() should also take care of non-printable characters because otherwise it's
> possible to trigger logfiles with control chars and that can lead in "cat logifle"
> unexpected executes code from untrusted input part of the logging

I'm not sure that's a real problem.  Why would anyone be executing log files?

And even if they did, it's not enough to have "magic contents" in a file to be a
problem, they also have to be at the correct offset in the file... which would be extremely hard to
guarantee for a log file, since you can't know in advance what's already been logged to
that file.

This seems like a non-issue.


Previous Comments:
------------------------------------------------------------------------
[2017-08-04 12:19:25] spam2 at rhsoft dot net

and error_log() should also take care of non-printable characters because otherwise it's
possible to trigger logfiles with control chars and that can lead in "cat logifle"
unexpected executes code from untrusted input part of the logging

------------------------------------------------------------------------
[2017-08-04 11:54:03] krakjoe@php.net

The fix is in the wrong place. The fix should be to modify the php_syslog function to conform with
expectations. I believe a more robust fix would be preferable ...

------------------------------------------------------------------------
[2017-07-26 16:35:11] philipp at redfish-solutions dot com

Can we please get movement on this?  There's a fix attached.

------------------------------------------------------------------------
[2017-07-11 04:16:42] philipp at redfish-solutions dot com

> yeah, that's how to create security issues as mod_rewrite did in case one did "cat
> logfile" leading to execute commands because of not properly filtered control chars

Sorry, not familiar with that CVE.  What are the details and how does it relate?

------------------------------------------------------------------------
[2017-07-05 23:26:03] spam2 at rhsoft dot net

> I don't think there is an overall conses on how to handle this, 
> the RFC suggests that a receiver has to deal with that if 
> non-printable (non-allowed) characters are used in the MSG part

yeah, that's how to create security issues as mod_rewrite did in case one did "cat
logfile" leading to execute commands because of not properly filtered control chars

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=74860


--
Edit this bug report at https://bugs.php.net/bug.php?id=74860&edit=1


Thread (24 messages)

« previous php.bugs (#210484) next »