Bug #73342 [Ver]: Vulnerability in php-fpm by changing stdin to non-blocking
| From: | nikic@php.net | Date: | Tue, 12 Jun 2018 18:42:15 +0000 |
| Subject: | Bug #73342 [Ver]: Vulnerability in php-fpm by changing stdin to non-blocking | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-215663@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=73342&edit=1
ID: 73342
Updated by: nikic@php.net
Reported by: xuavis at gmail dot com
Summary: Vulnerability in php-fpm by changing stdin to
non-blocking
Status: Verified
Type: Bug
Package: FPM related
Operating System: Ubuntu 16.04
PHP Version: 7.0Git-2016-10-18 (Git)
Assigned To: bukka
Block user comment: N
Private report: N
New Comment:
@bukka: PR up at https://github.com/php/php-src/pull/3287.
Previous Comments:
------------------------------------------------------------------------
[2018-06-12 17:45:40] nikic@php.net
@bukka: I can't remember writing it, but I have this test against the old infrastructure lying
around: https://gist.github.com/nikic/5904446746a7f90f98e856e6dda592ee
I'll port it and submit a PR.
------------------------------------------------------------------------
[2018-06-12 17:34:43] bukka@php.net
I just merged the test revamp. Think that the test for this could be similar to the one for
fastcgi_finish_request - https://git.io/vhrAj . Of course the PHP
code will be different (as test script) and there should be probably two requests and possibly some
other changes - not exactly sure atm. as I would have to try it but think you will get the idea ;)
------------------------------------------------------------------------
[2018-06-12 16:55:01] bukka@php.net
Btw. I would a bit careful as we are breaking FastCGI "spec" (it's not really a spec
though and it doesn't seem to be a useful part anywya) so maybe we should just target 7.2 first
and then possibly back port it. WDT?
------------------------------------------------------------------------
[2018-06-12 16:51:38] bukka@php.net
@nikic Please can you create a PR first. I will try to look at it this week and if I don't find
a time, go ahead but I think I should have time. Also a test should be present - that should be
quite easy to do in the new tests...
------------------------------------------------------------------------
[2018-06-12 16:34:37] nikic@php.net
@bukka: Thanks for the update. That sounds like things might still take a while, in which case I
will go ahead and merge this patch now. We can't afford to delay this issue by an indeterminate
amount of time, and given the production testing by kenny at kennynet dot co dot uk, I believe we
can be sufficiently confident in the correctness of the change.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=73342
--
Edit this bug report at https://bugs.php.net/bug.php?id=73342&edit=1