Bug #78557 [Csd->Opn]: PHP for Windows Elevation of Privilege

From: Date: Wed, 09 Oct 2019 04:56:30 +0000
Subject: Bug #78557 [Csd->Opn]: PHP for Windows Elevation of Privilege
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-223149@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78557&edit=1 ID: 78557 User updated by: zhutq2 at knownsec dot com Reported by: zhutq2 at knownsec dot com Summary: PHP for Windows Elevation of Privilege -Status: Closed +Status: Open Type: Bug Package: OpenSSL related Operating System: Windows 10 PHP Version: 7.3.9 Assigned To: cmb Block user comment: N Private report: N New Comment: > Resubmit comment to open the issue. I think this is a security issue in php and need a CVE-ID. As we all know, Openssl is an open source software library and anyone can use it. Openssl should responsible for itself, but it is not responsible for all software that uses it. Openssl fix the vulnerability(CVE-2019-1552) in 30 July 2019, But the openssl extention in php-src didn't keep in sync with openssl official. So the vulnerability still effect openssl extention until I report it. Build script and build parameters not in php-src source code but it is the base of php-src. You can't separate them. Curl for Windows has a similar vulnerability (CVE-2019-5443) [1][2] and I need a CVE-ID too. 1. <https://hackerone.com/reports/608577> 2. <https://curl.haxx.se/docs/CVE-2019-5443.html> Previous Comments: ------------------------------------------------------------------------ [2019-10-08 09:05:44] zhutq2 at knownsec dot com I revisited all previous comments, I think @cmb doesn't think this is a security issue because: This is not related to php-src, but rather to the Windows builds of OpenSSL. I don't think so. As we all know, Openssl is a open source software library and anyone can use it. Openssl should responsible for itself, but it is not responsible for all software that uses it. Openssl fix the vulnerability(CVE-2019-1552) in 30 July 2019, But the openssl extention in php-src didn't keep in sync with openssl official. So the vulnerability still effect openssl extention until I report it. Build script and build parameters not in php-src source code but it is the base of php-src. You can't separate them. Curl for Windows has a similar vulnerability (CVE-2019-5443) [1][2] and I need a CVE-ID too. 1. <https://hackerone.com/reports/608577> 2. <https://curl.haxx.se/docs/CVE-2019-5443.html> ------------------------------------------------------------------------ [2019-10-07 07:31:36] cmb@php.net The default OpenSSL config path has been changed for PHP 7.4+[1][2], the official PHP 7.4.0RC3 Windows builds already use this, and the docs now have a cautionary note regarding this issue, which is not a security issue per se. Therefore I'm (dis)closing this ticket. [1] <https://github.com/php/php-src/blob/b142e8a4b3e82c49600edc3469d09b4febb889ee/UPGRADING#L702-L704> [2] <http://svn.php.net/viewvc?view=revision&revision=348111> ------------------------------------------------------------------------ [2019-09-23 14:48:35] ab@php.net D'accord with Stas' suggestion, 7.4+ and doc is sufficient. Thanks. ------------------------------------------------------------------------ [2019-09-23 07:28:46] cmb@php.net > I think it makes sense to change it in master/7.4 […] ACK, we should consider that. This is, however, not related to php-src, but rather to the Windows builds of OpenSSL[1], and changing the default path would be as simple as changing the value of the --openssldir configure option, re-building the relevant packages, and re-building PHP. [1] <https://github.com/winlibs/openssl> [2] <https://wiki.php.net/internals/windows/libs#library_dependencies> ------------------------------------------------------------------------ [2019-09-23 07:03:02] zhutq2 at knownsec dot com Set the OPENSSL_CONF system environment variable in Windows system, not use putenv() function in php script, not set current user environment variable, too. Control Panel -> System and Security -> System -> Advanced system settings -> Advanced -> Environment Variables -> System variables -> New ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=78557 -- Edit this bug report at https://bugs.php.net/bug.php?id=78557&edit=1

« previous php.bugs (#223149) next »