Sec Bug->Bug #75211 [Opn->Nab]: SID can be overwritten
| From: | stas@php.net | Date: | Fri, 15 Sep 2017 19:17:52 +0000 |
| Subject: | Sec Bug->Bug #75211 [Opn->Nab]: SID can be overwritten | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-211181@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=75211&edit=1
ID: 75211
Updated by: stas@php.net
Reported by: cmb@php.net
Summary: SID can be overwritten
-Status: Open
+Status: Not a bug
-Type: Security
+Type: Bug
Package: Session related
Operating System: *
PHP Version: 7.0.23
Block user comment: N
Private report: Y
New Comment:
Thank you for taking the time to write to us, but this is not
a bug. Please double-check the documentation available at
http://www.php.net/manual/ and the instructions on how to
report
a bug at http://bugs.php.net/how-to-report.php
I don't see how it is a security issue. If you control the code, you can do anything. If you
specifically overwrote SID, then you get what you asked for. You can claim redefinition should not
work, but this has nothing to do with sessions or security.
Previous Comments:
------------------------------------------------------------------------
[2017-09-15 13:41:44] cmb@php.net
Description:
------------
The constant SID is defined to be case-insensitive[1], and as such
can be overwritten by userland code. This can cause serious issues
for applications which rely on SID === session_id() and allow
third-party plugins or addons to be installed.
Since the PHP manual states regarding SID[2]
| This is the same id as the one returned by session_id().
this appears to be a security issue.
[1] <https://github.com/php/php-src/blob/PHP-7.0.23/ext/session/session.c#L1551-L1559>
[2] <http://php.net/manual/en/session.constants.php>
Test script:
---------------
<?php
session_start();
const SID = 'foo';
echo SID, PHP_EOL, session_id(), PHP_EOL;
Expected result:
----------------
Either:
Notice: Constant SID already defined in %s on line %d
or:
krivgrliche9fetoif74o1iq21
krivgrliche9fetoif74o1iq21
or (at the very least):
fix the documentation
Actual result:
--------------
foo
krivgrliche9fetoif74o1iq21
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=75211&edit=1