Edit report at https://bugs.php.net/bug.php?id=74860&edit=1
ID: 74860
Updated by: ab@php.net
Reported by: philipp at redfish-solutions dot com
Summary: Uncaught exceptions not being formatted properly
when error_log set to "syslog"
-Status: Open
+Status: Closed
Type: Bug
Package: Output Control
Operating System: linux 4.9.30
PHP Version: 7.1.6
-Assigned To:
+Assigned To: ab
Block user comment: N
Private report: N
New Comment:
PR https://github.com/php/php-src/pull/2674
was merged.
Thanks.
Previous Comments:
------------------------------------------------------------------------
[2017-08-16 18:57:43] philipp at redfish-solutions dot com
> best practice is to avoid this whole discussion and just sanitize in one and for all at a
> central codepoint which is then used for everything dealing with write to logs and frankly it's
> likely done in a shorter time then discuss about it
The "central codepoint" would be the logger, in that case, which is what writes to the
file.
Not PHP, which is one of thousands of logging clients.
So you're effectively arguing for NOT fixing it in PHP if I've understood your point.
------------------------------------------------------------------------
[2017-08-15 20:50:52] philipp at redfish-solutions dot com
This is two separate but vaguely related issues, but they should not be conflated because the
considerations are very different.
Opening a separate bug report for the issue of how best to handle non NVT-ASCII, as bz #75077.
------------------------------------------------------------------------
[2017-08-08 08:57:52] spam2 at rhsoft dot net
you even quoted at your own "This version of Apache is vulnerable to escape character sequences
injection into error log.This problem may be exploited when a vulnerable terminal emulator is
used" in the meantime and NO it is NOT worth to dicusss where and if and when a vulnerable
terminal emulator may be used to view some logfile
best practice is to avoid this whole discussion and just sanitize in one and for all at a central
codepoint which is then used for everything dealing with write to logs and frankly it's likely
done in a shorter time then discuss about it
------------------------------------------------------------------------
[2017-08-07 23:57:37] philipp at redfish-solutions dot com
> what is your problem?
On 7/11/2017 I asked what the vulnerability was, i.e. CVE number, etc. and you never responded.
I've been very indulgent about a vulnerability which you still have to substantiate.
------------------------------------------------------------------------
[2017-08-07 05:01:24] spam2 at rhsoft dot net
what is your problem? i just pointed out that control chars has to be filtered at a central point so
that this affects syslog(), error_log(), trigger_error() and what not which leads in producing
logfiles - not more and not less - dunno why you needed to make dumb answers like "why would
anyone execute logfiles" and argue around at all
currently it just sucks that you need to filter logoutput in userland and in case of trigger_error
have no way to don't break the html page by not use htmlentities() while at the same time they
appear in the logfiles where nobody beeds them
so what is my point? that currently the whole error handling / logging is a complete mess
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=74860
--
Edit this bug report at https://bugs.php.net/bug.php?id=74860&edit=1