Bug #69948 [Asn->Csd]: path/domain are not sanitized in setcookie
| From: | cmb@php.net | Date: | Sat, 24 Mar 2018 16:32:48 +0000 |
| Subject: | Bug #69948 [Asn->Csd]: path/domain are not sanitized in setcookie | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-214466@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=69948&edit=1
ID: 69948
Updated by: cmb@php.net
Reported by: neal at fb dot com
Summary: path/domain are not sanitized in setcookie
-Status: Assigned
+Status: Closed
Type: Bug
Package: Network related
Operating System: N/A
PHP Version: 5.6.10
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of cmbecker69@gmx.de
Revision: http://git.php.net/?p=php-src.git;a=commit;h=5cb825df7251aeb28b297f071c35b227a3949f01
Log: Fix #69948: path/domain are not sanitized in setcookie
Previous Comments:
------------------------------------------------------------------------
[2018-03-10 16:33:50] cmb@php.net
PR: <https://github.com/php/php-src/pull/3179>
------------------------------------------------------------------------
[2015-06-28 11:49:30] cmb@php.net
The following patch has been added/updated:
Patch Name: 0001-Fix-69948
Revision: 1435492169
URL: https://bugs.php.net/patch-display.php?bug=69948&patch=0001-Fix-69948&revision=1435492169
------------------------------------------------------------------------
[2015-06-26 23:09:44] neal at fb dot com
Description:
------------
In the highly unlikely event where path or domain are user-controlled, it is possible to inject
semi-colons, equals signs, etc into a value. This allows you to provide arbitrary additional
key/value pairs inside of a Set-Cookie header (ie: set an expires header 20 years from now, add the
HttpOnly flag, etc).
There is already sanitization in the code for checking the "value" parameter: the same
logic should be applied to domain and path.
Test script:
---------------
<?php
setcookie('foo', 'bar', 0, $_GET['path'], $_GET['domain']);
Expected result:
----------------
Making a request with path=asdf;asdf&domain=foobar;%20secure results in no cookie being sent
(identical to how it's currently handled when the value has invalid characters).
Actual result:
--------------
Header looks like Set-Cookie: foo=bar; path=asdf;asdf; domain=foobar; secure
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=69948&edit=1