Bug #74860 [Com]: Uncaught exceptions not being formatted properly when error_log set to "syslog"

From: Date: Tue, 15 Aug 2017 20:50:53 +0000
Subject: Bug #74860 [Com]: Uncaught exceptions not being formatted properly when error_log set to "syslog"
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-210693@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=74860&edit=1 ID: 74860 Comment by: philipp at redfish-solutions dot com Reported by: philipp at redfish-solutions dot com Summary: Uncaught exceptions not being formatted properly when error_log set to "syslog" Status: Open Type: Bug Package: Output Control Operating System: linux 4.9.30 PHP Version: 7.1.6 Block user comment: N Private report: N New Comment: This is two separate but vaguely related issues, but they should not be conflated because the considerations are very different. Opening a separate bug report for the issue of how best to handle non NVT-ASCII, as bz #75077. Previous Comments: ------------------------------------------------------------------------ [2017-08-08 08:57:52] spam2 at rhsoft dot net you even quoted at your own "This version of Apache is vulnerable to escape character sequences injection into error log.This problem may be exploited when a vulnerable terminal emulator is used" in the meantime and NO it is NOT worth to dicusss where and if and when a vulnerable terminal emulator may be used to view some logfile best practice is to avoid this whole discussion and just sanitize in one and for all at a central codepoint which is then used for everything dealing with write to logs and frankly it's likely done in a shorter time then discuss about it ------------------------------------------------------------------------ [2017-08-07 23:57:37] philipp at redfish-solutions dot com > what is your problem? On 7/11/2017 I asked what the vulnerability was, i.e. CVE number, etc. and you never responded. I've been very indulgent about a vulnerability which you still have to substantiate. ------------------------------------------------------------------------ [2017-08-07 05:01:24] spam2 at rhsoft dot net what is your problem? i just pointed out that control chars has to be filtered at a central point so that this affects syslog(), error_log(), trigger_error() and what not which leads in producing logfiles - not more and not less - dunno why you needed to make dumb answers like "why would anyone execute logfiles" and argue around at all currently it just sucks that you need to filter logoutput in userland and in case of trigger_error have no way to don't break the html page by not use htmlentities() while at the same time they appear in the logfiles where nobody beeds them so what is my point? that currently the whole error handling / logging is a complete mess ------------------------------------------------------------------------ [2017-08-07 03:57:26] philipp at redfish-solutions dot com > yes, by simply sanitize *everything* passed to whatever function if it can contain untrusted > input and log output *clearly* falls in that scope You said to fix php_syslog(). I pointed out that this was a #define to syslog(). I *am* fixing the way we call syslog. Perhaps look at the patch first before telling me how it falls short. ------------------------------------------------------------------------ [2017-08-05 03:59:55] spam2 at rhsoft dot net > So how would I fix that? by simply sanitize the arguments passed to external libraries > There's a limited amount of bandwidth to secure systems, > and you need to expend your energy and resources wisely yes, by< simply sanitize *everything* passed to whatever function if it can contain untrusted input and log output *clearly* falls in that scope ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=74860 -- Edit this bug report at https://bugs.php.net/bug.php?id=74860&edit=1

« previous php.bugs (#210693) next »