Bug #78557 [Csd]: PHP for Windows Elevation of Privilege

From: Date: Tue, 08 Oct 2019 09:05:44 +0000
Subject: Bug #78557 [Csd]: PHP for Windows Elevation of Privilege
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-223131@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78557&edit=1 ID: 78557 User updated by: zhutq2 at knownsec dot com Reported by: zhutq2 at knownsec dot com Summary: PHP for Windows Elevation of Privilege Status: Closed Type: Bug Package: OpenSSL related Operating System: Windows 10 PHP Version: 7.3.9 Assigned To: cmb Block user comment: N Private report: N New Comment: I revisited all previous comments, I think @cmb doesn't think this is a security issue because: This is not related to php-src, but rather to the Windows builds of OpenSSL. I don't think so. As we all know, Openssl is a open source software library and anyone can use it. Openssl should responsible for itself, but it is not responsible for all software that uses it. Openssl fix the vulnerability(CVE-2019-1552) in 30 July 2019, But the openssl extention in php-src didn't keep in sync with openssl official. So the vulnerability still effect openssl extention until I report it. Build script and build parameters not in php-src source code but it is the base of php-src. You can't separate them. Curl for Windows has a similar vulnerability (CVE-2019-5443) [1][2] and I need a CVE-ID too. 1. <https://hackerone.com/reports/608577> 2. <https://curl.haxx.se/docs/CVE-2019-5443.html> Previous Comments: ------------------------------------------------------------------------ [2019-10-07 07:31:36] cmb@php.net The default OpenSSL config path has been changed for PHP 7.4+[1][2], the official PHP 7.4.0RC3 Windows builds already use this, and the docs now have a cautionary note regarding this issue, which is not a security issue per se. Therefore I'm (dis)closing this ticket. [1] <https://github.com/php/php-src/blob/b142e8a4b3e82c49600edc3469d09b4febb889ee/UPGRADING#L702-L704> [2] <http://svn.php.net/viewvc?view=revision&revision=348111> ------------------------------------------------------------------------ [2019-09-23 14:48:35] ab@php.net D'accord with Stas' suggestion, 7.4+ and doc is sufficient. Thanks. ------------------------------------------------------------------------ [2019-09-23 07:28:46] cmb@php.net > I think it makes sense to change it in master/7.4 […] ACK, we should consider that. This is, however, not related to php-src, but rather to the Windows builds of OpenSSL[1], and changing the default path would be as simple as changing the value of the --openssldir configure option, re-building the relevant packages, and re-building PHP. [1] <https://github.com/winlibs/openssl> [2] <https://wiki.php.net/internals/windows/libs#library_dependencies> ------------------------------------------------------------------------ [2019-09-23 07:03:02] zhutq2 at knownsec dot com Set the OPENSSL_CONF system environment variable in Windows system, not use putenv() function in php script, not set current user environment variable, too. Control Panel -> System and Security -> System -> Advanced system settings -> Advanced -> Environment Variables -> System variables -> New ------------------------------------------------------------------------ [2019-09-23 06:50:54] zhutq2 at knownsec dot com It seems that OPENSSL fixes a similar vulnerability(CVE-2019-1552) in some affected versions. You can find the description of CVE-2019-1552 and the git commit record in reference link. I think that when the user does not set the OPENSSL_CONF, SSLEAY_CONF environment variable, it is a good solution to load a openssl.cnf that cannot be controlled by a low-privileged user by default. For example: C:\Program Files (x86)\OpenSSL\ssl\openssl.cnf or C:\Program Files (x86)\Common Files\SSL\openssl.cnf. Add a note to the docs is good news for older versions of php. Users can avoid this vulnerability by setting the OPENSSL_CONF environment variable. [1] <https://www.openssl.org/news/vulnerabilities.html> [2] <https://www.openssl.org/news/secadv/20190730.txt> [3] <https://github.com/openssl/openssl/commit/54aa9d51b09d67e90db443f682cface795f5af9e> [4] <https://github.com/openssl/openssl/commit/e32bc855a81a2d48d215c506bdeb4f598045f7e9> ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=78557 -- Edit this bug report at https://bugs.php.net/bug.php?id=78557&edit=1

« previous php.bugs (#223131) next »