Bug #60677 [Ver->Csd]: CGI doesn't properly validate shebang line contains #!

From: Date: Mon, 15 Jul 2019 14:31:51 +0000
Subject: Bug #60677 [Ver->Csd]: CGI doesn't properly validate shebang line contains #!
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-221790@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=60677&edit=1 ID: 60677 Updated by: nikic@php.net Reported by: pasamio at gmail dot com Summary: CGI doesn't properly validate shebang line contains #! -Status: Verified +Status: Closed Type: Bug Package: CGI/CLI related Operating System: N/A PHP Version: PHP 5.6.7 -Assigned To: +Assigned To: nikic Block user comment: N Private report: N New Comment: Fixed by https://github.com/php/php-src/commit/c5f1b384b591009310370f0b06b10868d2d62741 for 7.4. Previous Comments: ------------------------------------------------------------------------ [2015-04-15 11:39:12] cmb@php.net Related To: Bug #69460 ------------------------------------------------------------------------ [2015-04-13 13:31:13] cmb@php.net The SVN related links are outdated. The relevant code is now: <https://github.com/php/php-src/blob/PHP-5.6.7/sapi/cgi/cgi_main.c#L2388-L2461> ------------------------------------------------------------------------ [2012-01-07 06:47:27] pasamio at gmail dot com The Apache 2 Handler appears to work properly though I can't find the code. Additionally the PHP CLI handles this correctly: http://svn.php.net/viewvc/php/php-src/trunk/sapi/cli/php_cli.c? revision=321634&view=markup Line 633 with: if (c == '#' && (c = fgetc(file_handle->handle.fp)) == '!') { And a later rewind. Should be sufficient for some of the CGI stuff but not all three of the instances in question. ------------------------------------------------------------------------ [2012-01-07 05:37:11] dtajchreber@php.net I completely misunderstood what you were saying... forgive me. :) Taking a second look, you're right... the logic only checks the first character when cgi.check_shebang_line = 1. ------------------------------------------------------------------------ [2012-01-07 05:20:05] dtajchreber@php.net Lines that begin with a hash tag can also be comments... # This is a comment... <?php echo 'None of this will appear!' ?> http://us.php.net/manual/en/language.basic-syntax.comments.php ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=60677 -- Edit this bug report at https://bugs.php.net/bug.php?id=60677&edit=1

« previous php.bugs (#221790) next »