Bug #78557 [Csd]: PHP for Windows Elevation of Privilege
| From: | zhutq2 at knownsec dot com | Date: | Tue, 08 Oct 2019 09:05:44 +0000 |
| Subject: | Bug #78557 [Csd]: PHP for Windows Elevation of Privilege | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-223131@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78557&edit=1
ID: 78557
User updated by: zhutq2 at knownsec dot com
Reported by: zhutq2 at knownsec dot com
Summary: PHP for Windows Elevation of Privilege
Status: Closed
Type: Bug
Package: OpenSSL related
Operating System: Windows 10
PHP Version: 7.3.9
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
I revisited all previous comments, I think @cmb doesn't think this is a security issue because:
This is not related to php-src, but rather to the Windows builds of OpenSSL.
I don't think so. As we all know, Openssl is a open source software library and anyone can use
it. Openssl should responsible for itself, but it is not responsible for all software that uses it.
Openssl fix the vulnerability(CVE-2019-1552) in 30 July 2019, But the openssl extention in php-src
didn't keep in sync with openssl official. So the vulnerability still effect openssl extention
until I report it. Build script and build parameters not in php-src source code but it is the base
of php-src. You can't separate them.
Curl for Windows has a similar vulnerability (CVE-2019-5443) [1][2] and I need a CVE-ID too.
1. <https://hackerone.com/reports/608577>
2. <https://curl.haxx.se/docs/CVE-2019-5443.html>
Previous Comments:
------------------------------------------------------------------------
[2019-10-07 07:31:36] cmb@php.net
The default OpenSSL config path has been changed for PHP
7.4+[1][2], the official PHP 7.4.0RC3 Windows builds already use
this, and the docs now have a cautionary note regarding this
issue, which is not a security issue per se. Therefore I'm
(dis)closing this ticket.
[1] <https://github.com/php/php-src/blob/b142e8a4b3e82c49600edc3469d09b4febb889ee/UPGRADING#L702-L704>
[2] <http://svn.php.net/viewvc?view=revision&revision=348111>
------------------------------------------------------------------------
[2019-09-23 14:48:35] ab@php.net
D'accord with Stas' suggestion, 7.4+ and doc is sufficient.
Thanks.
------------------------------------------------------------------------
[2019-09-23 07:28:46] cmb@php.net
> I think it makes sense to change it in master/7.4 [â¦]
ACK, we should consider that. This is, however, not related to
php-src, but rather to the Windows builds of OpenSSL[1], and
changing the default path would be as simple as changing the value
of the --openssldir configure option, re-building the relevant
packages, and re-building PHP.
[1] <https://github.com/winlibs/openssl>
[2] <https://wiki.php.net/internals/windows/libs#library_dependencies>
------------------------------------------------------------------------
[2019-09-23 07:03:02] zhutq2 at knownsec dot com
Set the OPENSSL_CONF system environment variable in Windows system, not use putenv() function in php
script, not set current user environment variable, too.
Control Panel -> System and Security -> System -> Advanced system settings -> Advanced
-> Environment Variables -> System variables -> New
------------------------------------------------------------------------
[2019-09-23 06:50:54] zhutq2 at knownsec dot com
It seems that OPENSSL fixes a similar vulnerability(CVE-2019-1552) in some affected versions. You
can find the description of CVE-2019-1552 and the git commit record in reference link.
I think that when the user does not set the OPENSSL_CONF, SSLEAY_CONF environment variable, it is a
good solution to load a openssl.cnf that cannot be controlled by a low-privileged user by default.
For example: C:\Program Files (x86)\OpenSSL\ssl\openssl.cnf or C:\Program Files (x86)\Common
Files\SSL\openssl.cnf.
Add a note to the docs is good news for older versions of php. Users can avoid this vulnerability by
setting the OPENSSL_CONF environment variable.
[1] <https://www.openssl.org/news/vulnerabilities.html>
[2] <https://www.openssl.org/news/secadv/20190730.txt>
[3] <https://github.com/openssl/openssl/commit/54aa9d51b09d67e90db443f682cface795f5af9e>
[4] <https://github.com/openssl/openssl/commit/e32bc855a81a2d48d215c506bdeb4f598045f7e9>
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=78557
--
Edit this bug report at https://bugs.php.net/bug.php?id=78557&edit=1