Bug #73342 [Ver]: Vulnerability in php-fpm by changing stdin to non-blocking

From: Date: Tue, 12 Jun 2018 18:42:15 +0000
Subject: Bug #73342 [Ver]: Vulnerability in php-fpm by changing stdin to non-blocking
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-215663@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73342&edit=1 ID: 73342 Updated by: nikic@php.net Reported by: xuavis at gmail dot com Summary: Vulnerability in php-fpm by changing stdin to non-blocking Status: Verified Type: Bug Package: FPM related Operating System: Ubuntu 16.04 PHP Version: 7.0Git-2016-10-18 (Git) Assigned To: bukka Block user comment: N Private report: N New Comment: @bukka: PR up at https://github.com/php/php-src/pull/3287. Previous Comments: ------------------------------------------------------------------------ [2018-06-12 17:45:40] nikic@php.net @bukka: I can't remember writing it, but I have this test against the old infrastructure lying around: https://gist.github.com/nikic/5904446746a7f90f98e856e6dda592ee I'll port it and submit a PR. ------------------------------------------------------------------------ [2018-06-12 17:34:43] bukka@php.net I just merged the test revamp. Think that the test for this could be similar to the one for fastcgi_finish_request - https://git.io/vhrAj . Of course the PHP code will be different (as test script) and there should be probably two requests and possibly some other changes - not exactly sure atm. as I would have to try it but think you will get the idea ;) ------------------------------------------------------------------------ [2018-06-12 16:55:01] bukka@php.net Btw. I would a bit careful as we are breaking FastCGI "spec" (it's not really a spec though and it doesn't seem to be a useful part anywya) so maybe we should just target 7.2 first and then possibly back port it. WDT? ------------------------------------------------------------------------ [2018-06-12 16:51:38] bukka@php.net @nikic Please can you create a PR first. I will try to look at it this week and if I don't find a time, go ahead but I think I should have time. Also a test should be present - that should be quite easy to do in the new tests... ------------------------------------------------------------------------ [2018-06-12 16:34:37] nikic@php.net @bukka: Thanks for the update. That sounds like things might still take a while, in which case I will go ahead and merge this patch now. We can't afford to delay this issue by an indeterminate amount of time, and given the production testing by kenny at kennynet dot co dot uk, I believe we can be sufficiently confident in the correctness of the change. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=73342 -- Edit this bug report at https://bugs.php.net/bug.php?id=73342&edit=1

« previous php.bugs (#215663) next »