Sec Bug->Bug #75889 [Opn]: Overloading disk with temporary files

From: Date: Thu, 01 Feb 2018 07:41:26 +0000
Subject: Sec Bug->Bug #75889 [Opn]: Overloading disk with temporary files
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-213774@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=75889&edit=1 ID: 75889 Updated by: stas@php.net Reported by: c dot r dot l dot f at yandex dot ru Summary: Overloading disk with temporary files Status: Open -Type: Security +Type: Bug Package: FPM related Operating System: Linux PHP Version: 7.1.13 Block user comment: N Private report: Y Previous Comments: ------------------------------------------------------------------------ [2018-02-01 02:21:53] c dot r dot l dot f at yandex dot ru Yep, I just checked it, it's not reproducible when file_uploads = Off. ------------------------------------------------------------------------ [2018-02-01 02:13:29] stas@php.net So do I understand correctly the problem does not exist when file uploads are disabled? ------------------------------------------------------------------------ [2018-02-01 02:06:42] c dot r dot l dot f at yandex dot ru In default installations files uploads is always on, so any host that satisfies the dependencies (PHP+NGINX) can be attacked. Please look video PoC: https://alt3r.eg0.ru/p0c5/12a636fcab5953233706dadacfff3ba8.avi ------------------------------------------------------------------------ [2018-02-01 01:36:58] stas@php.net Isn't that always the case when uploads are allowed - you can upload files until out of disk space, absent other limitations like quotas, etc.? ------------------------------------------------------------------------ [2018-02-01 01:01:32] c dot r dot l dot f at yandex dot ru The problem is that PHP does not delete created temporary files (rfc1867) after connection is closed. In the provided scenario, NGINX closes the connection before PHP writes something in it. Judging by the logs of strace, PHP gets SIGPIPE and for some reasons does not clear temporary files. Thus, the attacker can upload temporary files while disk space is available. Only reboot or manual deleting this files will help. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=75889 -- Edit this bug report at https://bugs.php.net/bug.php?id=75889&edit=1

« previous php.bugs (#213774) next »