Sec Bug->Bug #78557 [Asn->Csd]: PHP for Windows Elevation of Privilege

From: Date: Mon, 07 Oct 2019 07:31:36 +0000
Subject: Sec Bug->Bug #78557 [Asn->Csd]: PHP for Windows Elevation of Privilege
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-223104@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78557&edit=1 ID: 78557 Updated by: cmb@php.net Reported by: zhutq2 at knownsec dot com Summary: PHP for Windows Elevation of Privilege -Status: Assigned +Status: Closed -Type: Security +Type: Bug Package: OpenSSL related Operating System: Windows 10 PHP Version: 7.3.9 Assigned To: cmb Block user comment: N Private report: Y New Comment: The default OpenSSL config path has been changed for PHP 7.4+[1][2], the official PHP 7.4.0RC3 Windows builds already use this, and the docs now have a cautionary note regarding this issue, which is not a security issue per se. Therefore I'm (dis)closing this ticket. [1] <https://github.com/php/php-src/blob/b142e8a4b3e82c49600edc3469d09b4febb889ee/UPGRADING#L702-L704> [2] <http://svn.php.net/viewvc?view=revision&revision=348111> Previous Comments: ------------------------------------------------------------------------ [2019-09-23 14:48:35] ab@php.net D'accord with Stas' suggestion, 7.4+ and doc is sufficient. Thanks. ------------------------------------------------------------------------ [2019-09-23 07:28:46] cmb@php.net > I think it makes sense to change it in master/7.4 […] ACK, we should consider that. This is, however, not related to php-src, but rather to the Windows builds of OpenSSL[1], and changing the default path would be as simple as changing the value of the --openssldir configure option, re-building the relevant packages, and re-building PHP. [1] <https://github.com/winlibs/openssl> [2] <https://wiki.php.net/internals/windows/libs#library_dependencies> ------------------------------------------------------------------------ [2019-09-23 07:03:02] zhutq2 at knownsec dot com Set the OPENSSL_CONF system environment variable in Windows system, not use putenv() function in php script, not set current user environment variable, too. Control Panel -> System and Security -> System -> Advanced system settings -> Advanced -> Environment Variables -> System variables -> New ------------------------------------------------------------------------ [2019-09-23 06:50:54] zhutq2 at knownsec dot com It seems that OPENSSL fixes a similar vulnerability(CVE-2019-1552) in some affected versions. You can find the description of CVE-2019-1552 and the git commit record in reference link. I think that when the user does not set the OPENSSL_CONF, SSLEAY_CONF environment variable, it is a good solution to load a openssl.cnf that cannot be controlled by a low-privileged user by default. For example: C:\Program Files (x86)\OpenSSL\ssl\openssl.cnf or C:\Program Files (x86)\Common Files\SSL\openssl.cnf. Add a note to the docs is good news for older versions of php. Users can avoid this vulnerability by setting the OPENSSL_CONF environment variable. [1] <https://www.openssl.org/news/vulnerabilities.html> [2] <https://www.openssl.org/news/secadv/20190730.txt> [3] <https://github.com/openssl/openssl/commit/54aa9d51b09d67e90db443f682cface795f5af9e> [4] <https://github.com/openssl/openssl/commit/e32bc855a81a2d48d215c506bdeb4f598045f7e9> ------------------------------------------------------------------------ [2019-09-22 19:05:22] stas@php.net I think it makes sense to change it in master/7.4 if openssl changed it, and add a note in UPGRADING. Maybe also add a note to the docs. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=78557 -- Edit this bug report at https://bugs.php.net/bug.php?id=78557&edit=1

« previous php.bugs (#223104) next »