Sec Bug->Bug #76894 [Opn]: imageftbbox - listing files outside of openbase_dir
| From: | cmb@php.net | Date: | Mon, 17 Sep 2018 15:14:27 +0000 |
| Subject: | Sec Bug->Bug #76894 [Opn]: imageftbbox - listing files outside of openbase_dir | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-217100@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=76894&edit=1
ID: 76894
Updated by: cmb@php.net
Reported by: fernando at null-life dot com
Summary: imageftbbox - listing files outside of openbase_dir
Status: Open
-Type: Security
+Type: Bug
Package: GD related
PHP Version: 7.2.10
Block user comment: N
Private report: Y
New Comment:
According to our security classification[1] this is not a
security issue, since it:
| requires the use of settings not recommended for production -
| ex. error reporting to output
It seems strange that ZTS versions do not issue the open_basedir
restriction warning for non-existant files, but since the other
warning is the result of a failing open_basedir check, that's a
minor issue.
[1] <https://wiki.php.net/security>
Previous Comments:
------------------------------------------------------------------------
[2018-09-17 04:04:57] fernando at null-life dot com
Description:
------------
When specifying a file that is outside of the openbasedir path, imageftbbox emits two warnings when
the file used as a font exists, and only one when it doesn't. This allows to identify existing
paths/files. I'm testing on Windows only.
For example:
imageftbbox(10, 0, "C:\\windows", 'PHP');
Warning: imageftbbox(): open_basedir restriction in effect. File(c:\windows) is not within the
allowed path(s): (C:\tools\phuzzer) in C:\tools\phuzzer\imageft.php on line 15
Warning: imageftbbox(): Invalid font filename in C:\tools\phuzzer\imageft.php on line 15
Test script:
---------------
php.exe -n -dopen_basedir=C:\tools\phuzzer -dextension=ext\php_gd2.dll imageft.php
<?php
function myErrorHandler($errno, $errstr, $errfile, $errline) {
global $errorsgenerated;
$errorsgenerated = $errorsgenerated + 1;
return true;
}
set_error_handler('myErrorHandler');
function file_exists_openbasedir($path) {
global $errorsgenerated;
$errorsgenerated = 0;
imageftbbox(10, 0, $path, 'PHP');
return $errorsgenerated > 1;
}
echo "c:\\anythingelse ".(file_exists_openbasedir("c:\\anythingelse") ?
"exists" : "doesnt exist").PHP_EOL;
echo "c:\\windows ".(file_exists_openbasedir("c:\\windows")? "exists"
: "doesnt exist").PHP_EOL;
Expected result:
----------------
Same behavior regardless the file exists or no.
Actual result:
--------------
c:\anythingelse doesnt exist
c:\windows exists
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=76894&edit=1