Bug #77496 [Com]: mysqli->real_connect() overwrites MYSQLI_OPT_LOCAL_INFILE setting

From: Date: Wed, 23 Jan 2019 10:32:55 +0000
Subject: Bug #77496 [Com]: mysqli->real_connect() overwrites MYSQLI_OPT_LOCAL_INFILE setting
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-219148@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77496&edit=1

 ID:                 77496
 Comment by:         spam2 at rhsoft dot net
 Reported by:        php at yghe dot net
 Summary:            mysqli->real_connect() overwrites
                     MYSQLI_OPT_LOCAL_INFILE setting
 Status:             Verified
 Type:               Bug
 Package:            MySQLi related
 Operating System:   Mac OS X Mojave 10.14.2
 PHP Version:        7.3.1
 Block user comment: N
 Private report:     N

 New Comment:

>> I'd like to point out that this actually is a security issue.
> ...in the application

this arrogance when MYSQLI_OPT_LOCAL_INFILE in the application should prevent issues like https://gwillem.gitlab.io/2019/01/17/adminer-4.6.2-file-disclosure-vulnerability/


Previous Comments:
------------------------------------------------------------------------
[2019-01-22 17:10:17] spam2 at rhsoft dot net

the distinction in this bugtracker is more than questionable and how security relevant bad behavior
is treated is terrible at all and has a broader impact:

distributions which are doing only backports of security bugfixes when everything is handeled
"it's not a security bug"

this general attitude is part of PHP's bad reputation

------------------------------------------------------------------------
[2019-01-22 16:58:31] requinix@php.net

> I'd like to point out that this actually is a security issue.
...in the application. Not in PHP. There's a distinction there often lost in the commentary on
this bug tracker.

------------------------------------------------------------------------
[2019-01-22 11:17:08] hanno at hboeck dot de

I'd like to point out that this actually is a security issue.

LOCAL INFILE can be used by a malicious server to exfiltrate files from the client. Disabling this
option thus can certainly have security implications.

This caused an issue in phpmyadmin where they thought they set that option, but it wasn't
active:
https://github.com/phpmyadmin/phpmyadmin/commit/c5e01f84ad48c5c626001cb92d7a95500920a900

------------------------------------------------------------------------
[2019-01-22 00:50:25] cmb@php.net

Thanks, Damian!

------------------------------------------------------------------------
[2019-01-22 00:47:18] requinix@php.net

I hit Enter as a reflex, wasn't ready...

Came from the migration to mysqlnd.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=77496


--
Edit this bug report at https://bugs.php.net/bug.php?id=77496&edit=1


Thread (11 messages)

« previous php.bugs (#219148) next »