Sec Bug->Bug #75211 [Opn->Nab]: SID can be overwritten

From: Date: Fri, 15 Sep 2017 19:17:52 +0000
Subject: Sec Bug->Bug #75211 [Opn->Nab]: SID can be overwritten
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-211181@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=75211&edit=1 ID: 75211 Updated by: stas@php.net Reported by: cmb@php.net Summary: SID can be overwritten -Status: Open +Status: Not a bug -Type: Security +Type: Bug Package: Session related Operating System: * PHP Version: 7.0.23 Block user comment: N Private report: Y New Comment: Thank you for taking the time to write to us, but this is not a bug. Please double-check the documentation available at http://www.php.net/manual/ and the instructions on how to report a bug at http://bugs.php.net/how-to-report.php I don't see how it is a security issue. If you control the code, you can do anything. If you specifically overwrote SID, then you get what you asked for. You can claim redefinition should not work, but this has nothing to do with sessions or security. Previous Comments: ------------------------------------------------------------------------ [2017-09-15 13:41:44] cmb@php.net Description: ------------ The constant SID is defined to be case-insensitive[1], and as such can be overwritten by userland code. This can cause serious issues for applications which rely on SID === session_id() and allow third-party plugins or addons to be installed. Since the PHP manual states regarding SID[2] | This is the same id as the one returned by session_id(). this appears to be a security issue. [1] <https://github.com/php/php-src/blob/PHP-7.0.23/ext/session/session.c#L1551-L1559> [2] <http://php.net/manual/en/session.constants.php> Test script: --------------- <?php session_start(); const SID = 'foo'; echo SID, PHP_EOL, session_id(), PHP_EOL; Expected result: ---------------- Either: Notice: Constant SID already defined in %s on line %d or: krivgrliche9fetoif74o1iq21 krivgrliche9fetoif74o1iq21 or (at the very least): fix the documentation Actual result: -------------- foo krivgrliche9fetoif74o1iq21 ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=75211&edit=1

« previous php.bugs (#211181) next »