Sec Bug->Bug #75077 [Opn]: syslog messages need to be checked for conformance with RFC-3164 and RFC-5424
| From: | stas@php.net | Date: | Sat, 19 Aug 2017 04:35:43 +0000 |
| Subject: | Sec Bug->Bug #75077 [Opn]: syslog messages need to be checked for conformance with RFC-3164 and RFC-5424 | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-210739@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=75077&edit=1
ID: 75077
Updated by: stas@php.net
Reported by: philipp at redfish-solutions dot com
Summary: syslog messages need to be checked for conformance
with RFC-3164 and RFC-5424
Status: Open
-Type: Security
+Type: Bug
-Package: Output Control
+Package: Unknown/Other Function
Operating System: linux 4.9.40
PHP Version: 7.1.8
Block user comment: N
Private report: Y
Previous Comments:
------------------------------------------------------------------------
[2017-08-16 19:16:03] philipp at redfish-solutions dot com
The more I think about this, the less I think it should be a security bug since there's nothing
specific to PHP that makes it the vulnerability. Can we please change this to "BUG"
instead?
------------------------------------------------------------------------
[2017-08-15 20:47:21] philipp at redfish-solutions dot com
Description:
------------
This issue came up in the discussions for bz #74860.
Basically, the only type of message explicitly and unequivocally allowed by the Syslog RFC's is
NVT ASCII (i.e. hex characters 0x20-0x7E).
UTF-8 maybe used in compressed (shortest form) but it must be prefixed with a BOM (0xEF,0xBB,0xBF).
Also, see the discussion for PR #2674.
Test script:
---------------
<?php
ini_set("error_log", "syslog");
error_log("h\364pital stra\337e", 0);
error_log("this string \321\032\003", 0);
?>
Expected result:
----------------
It's not obvious what the correct behavior is in legacy cases which violate the RFC's.
Actual result:
--------------
Aug 15 14:43:07 ubuntu16 php7.0: h?pital stra?e
Aug 15 14:43:07 ubuntu16 php7.0: this string ?#032#003
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=75077&edit=1