Sec Bug->Bug #76894 [Opn]: imageftbbox - listing files outside of openbase_dir

From: Date: Mon, 17 Sep 2018 15:14:27 +0000
Subject: Sec Bug->Bug #76894 [Opn]: imageftbbox - listing files outside of openbase_dir
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-217100@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76894&edit=1 ID: 76894 Updated by: cmb@php.net Reported by: fernando at null-life dot com Summary: imageftbbox - listing files outside of openbase_dir Status: Open -Type: Security +Type: Bug Package: GD related PHP Version: 7.2.10 Block user comment: N Private report: Y New Comment: According to our security classification[1] this is not a security issue, since it: | requires the use of settings not recommended for production - | ex. error reporting to output It seems strange that ZTS versions do not issue the open_basedir restriction warning for non-existant files, but since the other warning is the result of a failing open_basedir check, that's a minor issue. [1] <https://wiki.php.net/security> Previous Comments: ------------------------------------------------------------------------ [2018-09-17 04:04:57] fernando at null-life dot com Description: ------------ When specifying a file that is outside of the openbasedir path, imageftbbox emits two warnings when the file used as a font exists, and only one when it doesn't. This allows to identify existing paths/files. I'm testing on Windows only. For example: imageftbbox(10, 0, "C:\\windows", 'PHP'); Warning: imageftbbox(): open_basedir restriction in effect. File(c:\windows) is not within the allowed path(s): (C:\tools\phuzzer) in C:\tools\phuzzer\imageft.php on line 15 Warning: imageftbbox(): Invalid font filename in C:\tools\phuzzer\imageft.php on line 15 Test script: --------------- php.exe -n -dopen_basedir=C:\tools\phuzzer -dextension=ext\php_gd2.dll imageft.php <?php function myErrorHandler($errno, $errstr, $errfile, $errline) { global $errorsgenerated; $errorsgenerated = $errorsgenerated + 1; return true; } set_error_handler('myErrorHandler'); function file_exists_openbasedir($path) { global $errorsgenerated; $errorsgenerated = 0; imageftbbox(10, 0, $path, 'PHP'); return $errorsgenerated > 1; } echo "c:\\anythingelse ".(file_exists_openbasedir("c:\\anythingelse") ? "exists" : "doesnt exist").PHP_EOL; echo "c:\\windows ".(file_exists_openbasedir("c:\\windows")? "exists" : "doesnt exist").PHP_EOL; Expected result: ---------------- Same behavior regardless the file exists or no. Actual result: -------------- c:\anythingelse doesnt exist c:\windows exists ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=76894&edit=1

« previous php.bugs (#217100) next »