Bug #78557 [Csd->Opn]: PHP for Windows Elevation of Privilege
| From: | zhutq2 at knownsec dot com | Date: | Wed, 09 Oct 2019 04:56:30 +0000 |
| Subject: | Bug #78557 [Csd->Opn]: PHP for Windows Elevation of Privilege | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-223149@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78557&edit=1
ID: 78557
User updated by: zhutq2 at knownsec dot com
Reported by: zhutq2 at knownsec dot com
Summary: PHP for Windows Elevation of Privilege
-Status: Closed
+Status: Open
Type: Bug
Package: OpenSSL related
Operating System: Windows 10
PHP Version: 7.3.9
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
> Resubmit comment to open the issue. I think this is a security issue in php and need a CVE-ID.
As we all know, Openssl is an open source software library and anyone can use it. Openssl should
responsible for itself, but it is not responsible for all software that uses it.
Openssl fix the vulnerability(CVE-2019-1552) in 30 July 2019, But the openssl extention in php-src
didn't keep in sync with openssl official. So the vulnerability still effect openssl extention
until I report it. Build script and build parameters not in php-src source code but it is the base
of php-src. You can't separate them.
Curl for Windows has a similar vulnerability (CVE-2019-5443) [1][2] and I need a CVE-ID too.
1. <https://hackerone.com/reports/608577>
2. <https://curl.haxx.se/docs/CVE-2019-5443.html>
Previous Comments:
------------------------------------------------------------------------
[2019-10-08 09:05:44] zhutq2 at knownsec dot com
I revisited all previous comments, I think @cmb doesn't think this is a security issue because:
This is not related to php-src, but rather to the Windows builds of OpenSSL.
I don't think so. As we all know, Openssl is a open source software library and anyone can use
it. Openssl should responsible for itself, but it is not responsible for all software that uses it.
Openssl fix the vulnerability(CVE-2019-1552) in 30 July 2019, But the openssl extention in php-src
didn't keep in sync with openssl official. So the vulnerability still effect openssl extention
until I report it. Build script and build parameters not in php-src source code but it is the base
of php-src. You can't separate them.
Curl for Windows has a similar vulnerability (CVE-2019-5443) [1][2] and I need a CVE-ID too.
1. <https://hackerone.com/reports/608577>
2. <https://curl.haxx.se/docs/CVE-2019-5443.html>
------------------------------------------------------------------------
[2019-10-07 07:31:36] cmb@php.net
The default OpenSSL config path has been changed for PHP
7.4+[1][2], the official PHP 7.4.0RC3 Windows builds already use
this, and the docs now have a cautionary note regarding this
issue, which is not a security issue per se. Therefore I'm
(dis)closing this ticket.
[1] <https://github.com/php/php-src/blob/b142e8a4b3e82c49600edc3469d09b4febb889ee/UPGRADING#L702-L704>
[2] <http://svn.php.net/viewvc?view=revision&revision=348111>
------------------------------------------------------------------------
[2019-09-23 14:48:35] ab@php.net
D'accord with Stas' suggestion, 7.4+ and doc is sufficient.
Thanks.
------------------------------------------------------------------------
[2019-09-23 07:28:46] cmb@php.net
> I think it makes sense to change it in master/7.4 [â¦]
ACK, we should consider that. This is, however, not related to
php-src, but rather to the Windows builds of OpenSSL[1], and
changing the default path would be as simple as changing the value
of the --openssldir configure option, re-building the relevant
packages, and re-building PHP.
[1] <https://github.com/winlibs/openssl>
[2] <https://wiki.php.net/internals/windows/libs#library_dependencies>
------------------------------------------------------------------------
[2019-09-23 07:03:02] zhutq2 at knownsec dot com
Set the OPENSSL_CONF system environment variable in Windows system, not use putenv() function in php
script, not set current user environment variable, too.
Control Panel -> System and Security -> System -> Advanced system settings -> Advanced
-> Environment Variables -> System variables -> New
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=78557
--
Edit this bug report at https://bugs.php.net/bug.php?id=78557&edit=1