Sec Bug->Bug #76469 [Opn->Nab]: Bad call to ldap_bind not setting error in ldap_errno

From: Date: Wed, 13 Jun 2018 14:21:55 +0000
Subject: Sec Bug->Bug #76469 [Opn->Nab]: Bad call to ldap_bind not setting error in ldap_errno
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-215694@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76469&edit=1 ID: 76469 Updated by: cmb@php.net Reported by: clement dot oudot at worteks dot com Summary: Bad call to ldap_bind not setting error in ldap_errno -Status: Open +Status: Not a bug -Type: Security +Type: Bug Package: LDAP related Operating System: GNU/Linux PHP Version: 7.1.18 -Assigned To: +Assigned To: cmb Block user comment: N Private report: Y New Comment: Thank you for taking the time to write to us, but this is not a bug. Please double-check the documentation available at http://www.php.net/manual/ and the instructions on how to report a bug at http://bugs.php.net/how-to-report.php Passing values of unsupported types to built-in functions is a userland programming error. If you want to be extra sure that this doesn't happen, use declare(strict_types=1). Previous Comments: ------------------------------------------------------------------------ [2018-06-13 13:47:47] clement dot oudot at worteks dot com Description: ------------ When using an array as password when calling ldap_bind, we have a warning but ldap_errno is not reset, so we keep the value of the previous LDAP operation. As a lot of PHP code rely on ldap_errno to check if bind is successful, we a major security issue here: sending an array as GET/POST parameter to login age can bypass authentication if the code relies on errno. Test script: --------------- <?php error_reporting(0); $badpassword = "test"; $goodpassword = "secret"; $bugpassword[] = "a"; $ldap = ldap_connect("ldap://localhost"); ldap_set_option($ldap, LDAP_OPT_PROTOCOL_VERSION, 3); ldap_set_option($ldap, LDAP_OPT_REFERRALS, 0); $bind = ldap_bind( $ldap, "cn=admin,dc=example,dc=com" , $badpassword ); $errno = ldap_errno($ldap); echo "Bind 1 returns $errno\n"; $bind = ldap_bind( $ldap, "cn=admin,dc=example,dc=com" , $goodpassword ); $errno = ldap_errno($ldap); echo "Bind 2 returns $errno\n"; $bind = ldap_bind( $ldap, "cn=admin,dc=example,dc=com" , $bugpassword ); $errno = ldap_errno($ldap); echo "Bind 3 returns $errno\n"; Expected result: ---------------- Bind 1 returns 49 Bind 2 returns 0 Bind 3 returns 49 # or any error code Actual result: -------------- Bind 1 returns 49 Bind 2 returns 0 Bind 3 returns 0 ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=76469&edit=1

« previous php.bugs (#215694) next »