Edit report at https://bugs.php.net/bug.php?id=74860&edit=1
ID: 74860
Comment by: spam2 at rhsoft dot net
Reported by: philipp at redfish-solutions dot com
Summary: Uncaught exceptions not being formatted properly
when error_log set to "syslog"
Status: Open
Type: Bug
Package: Output Control
Operating System: linux 4.9.30
PHP Version: 7.1.6
Block user comment: N
Private report: N
New Comment:
you clearly did not understand what I was talking about: with control chars in a text file it is
possible that a simple "cat filename" leads to execute code sequences in the shell and
some time ago there was even a CVE for mod_security lacking proper escapeing leading to execute code
by just display the log file
Previous Comments:
------------------------------------------------------------------------
[2017-08-04 18:54:08] philipp at redfish-solutions dot com
> and error_log() should also take care of non-printable characters because otherwise it's
> possible to trigger logfiles with control chars and that can lead in "cat logifle"
> unexpected executes code from untrusted input part of the logging
I'm not sure that's a real problem. Why would anyone be executing log files?
And even if they did, it's not enough to have "magic contents" in a file to be a
problem, they also have to be at the correct offset in the file... which would be extremely hard to
guarantee for a log file, since you can't know in advance what's already been logged to
that file.
This seems like a non-issue.
------------------------------------------------------------------------
[2017-08-04 12:19:25] spam2 at rhsoft dot net
and error_log() should also take care of non-printable characters because otherwise it's
possible to trigger logfiles with control chars and that can lead in "cat logifle"
unexpected executes code from untrusted input part of the logging
------------------------------------------------------------------------
[2017-08-04 11:54:03] krakjoe@php.net
The fix is in the wrong place. The fix should be to modify the php_syslog function to conform with
expectations. I believe a more robust fix would be preferable ...
------------------------------------------------------------------------
[2017-07-26 16:35:11] philipp at redfish-solutions dot com
Can we please get movement on this? There's a fix attached.
------------------------------------------------------------------------
[2017-07-11 04:16:42] philipp at redfish-solutions dot com
> yeah, that's how to create security issues as mod_rewrite did in case one did "cat
> logfile" leading to execute commands because of not properly filtered control chars
Sorry, not familiar with that CVE. What are the details and how does it relate?
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=74860
--
Edit this bug report at https://bugs.php.net/bug.php?id=74860&edit=1