Sec Bug->Bug #78557 [Asn->Csd]: PHP for Windows Elevation of Privilege
| From: | cmb@php.net | Date: | Mon, 07 Oct 2019 07:31:36 +0000 |
| Subject: | Sec Bug->Bug #78557 [Asn->Csd]: PHP for Windows Elevation of Privilege | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-223104@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78557&edit=1
ID: 78557
Updated by: cmb@php.net
Reported by: zhutq2 at knownsec dot com
Summary: PHP for Windows Elevation of Privilege
-Status: Assigned
+Status: Closed
-Type: Security
+Type: Bug
Package: OpenSSL related
Operating System: Windows 10
PHP Version: 7.3.9
Assigned To: cmb
Block user comment: N
Private report: Y
New Comment:
The default OpenSSL config path has been changed for PHP
7.4+[1][2], the official PHP 7.4.0RC3 Windows builds already use
this, and the docs now have a cautionary note regarding this
issue, which is not a security issue per se. Therefore I'm
(dis)closing this ticket.
[1] <https://github.com/php/php-src/blob/b142e8a4b3e82c49600edc3469d09b4febb889ee/UPGRADING#L702-L704>
[2] <http://svn.php.net/viewvc?view=revision&revision=348111>
Previous Comments:
------------------------------------------------------------------------
[2019-09-23 14:48:35] ab@php.net
D'accord with Stas' suggestion, 7.4+ and doc is sufficient.
Thanks.
------------------------------------------------------------------------
[2019-09-23 07:28:46] cmb@php.net
> I think it makes sense to change it in master/7.4 [â¦]
ACK, we should consider that. This is, however, not related to
php-src, but rather to the Windows builds of OpenSSL[1], and
changing the default path would be as simple as changing the value
of the --openssldir configure option, re-building the relevant
packages, and re-building PHP.
[1] <https://github.com/winlibs/openssl>
[2] <https://wiki.php.net/internals/windows/libs#library_dependencies>
------------------------------------------------------------------------
[2019-09-23 07:03:02] zhutq2 at knownsec dot com
Set the OPENSSL_CONF system environment variable in Windows system, not use putenv() function in php
script, not set current user environment variable, too.
Control Panel -> System and Security -> System -> Advanced system settings -> Advanced
-> Environment Variables -> System variables -> New
------------------------------------------------------------------------
[2019-09-23 06:50:54] zhutq2 at knownsec dot com
It seems that OPENSSL fixes a similar vulnerability(CVE-2019-1552) in some affected versions. You
can find the description of CVE-2019-1552 and the git commit record in reference link.
I think that when the user does not set the OPENSSL_CONF, SSLEAY_CONF environment variable, it is a
good solution to load a openssl.cnf that cannot be controlled by a low-privileged user by default.
For example: C:\Program Files (x86)\OpenSSL\ssl\openssl.cnf or C:\Program Files (x86)\Common
Files\SSL\openssl.cnf.
Add a note to the docs is good news for older versions of php. Users can avoid this vulnerability by
setting the OPENSSL_CONF environment variable.
[1] <https://www.openssl.org/news/vulnerabilities.html>
[2] <https://www.openssl.org/news/secadv/20190730.txt>
[3] <https://github.com/openssl/openssl/commit/54aa9d51b09d67e90db443f682cface795f5af9e>
[4] <https://github.com/openssl/openssl/commit/e32bc855a81a2d48d215c506bdeb4f598045f7e9>
------------------------------------------------------------------------
[2019-09-22 19:05:22] stas@php.net
I think it makes sense to change it in master/7.4 if openssl changed it, and add a note in
UPGRADING. Maybe also add a note to the docs.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=78557
--
Edit this bug report at https://bugs.php.net/bug.php?id=78557&edit=1