Sec Bug->Bug #76469 [Opn->Nab]: Bad call to ldap_bind not setting error in ldap_errno
| From: | cmb@php.net | Date: | Wed, 13 Jun 2018 14:21:55 +0000 |
| Subject: | Sec Bug->Bug #76469 [Opn->Nab]: Bad call to ldap_bind not setting error in ldap_errno | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-215694@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=76469&edit=1
ID: 76469
Updated by: cmb@php.net
Reported by: clement dot oudot at worteks dot com
Summary: Bad call to ldap_bind not setting error in
ldap_errno
-Status: Open
+Status: Not a bug
-Type: Security
+Type: Bug
Package: LDAP related
Operating System: GNU/Linux
PHP Version: 7.1.18
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: Y
New Comment:
Thank you for taking the time to write to us, but this is not
a bug. Please double-check the documentation available at
http://www.php.net/manual/ and the instructions on how to
report
a bug at http://bugs.php.net/how-to-report.php
Passing values of unsupported types to built-in functions is a
userland programming error. If you want to be extra sure that
this doesn't happen, use
declare(strict_types=1).
Previous Comments:
------------------------------------------------------------------------
[2018-06-13 13:47:47] clement dot oudot at worteks dot com
Description:
------------
When using an array as password when calling ldap_bind, we have a warning but ldap_errno is not
reset, so we keep the value of the previous LDAP operation.
As a lot of PHP code rely on ldap_errno to check if bind is successful, we a major security issue
here: sending an array as GET/POST parameter to login age can bypass authentication if the code
relies on errno.
Test script:
---------------
<?php
error_reporting(0);
$badpassword = "test";
$goodpassword = "secret";
$bugpassword[] = "a";
$ldap = ldap_connect("ldap://localhost");
ldap_set_option($ldap, LDAP_OPT_PROTOCOL_VERSION, 3);
ldap_set_option($ldap, LDAP_OPT_REFERRALS, 0);
$bind = ldap_bind( $ldap, "cn=admin,dc=example,dc=com" , $badpassword );
$errno = ldap_errno($ldap);
echo "Bind 1 returns $errno\n";
$bind = ldap_bind( $ldap, "cn=admin,dc=example,dc=com" , $goodpassword );
$errno = ldap_errno($ldap);
echo "Bind 2 returns $errno\n";
$bind = ldap_bind( $ldap, "cn=admin,dc=example,dc=com" , $bugpassword );
$errno = ldap_errno($ldap);
echo "Bind 3 returns $errno\n";
Expected result:
----------------
Bind 1 returns 49
Bind 2 returns 0
Bind 3 returns 49 # or any error code
Actual result:
--------------
Bind 1 returns 49
Bind 2 returns 0
Bind 3 returns 0
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=76469&edit=1