Bug #78557 [Opn->Csd]: PHP for Windows Elevation of Privilege
| From: | cmb@php.net | Date: | Wed, 09 Oct 2019 09:44:16 +0000 |
| Subject: | Bug #78557 [Opn->Csd]: PHP for Windows Elevation of Privilege | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-223154@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78557&edit=1
ID: 78557
Updated by: cmb@php.net
Reported by: zhutq2 at knownsec dot com
Summary: PHP for Windows Elevation of Privilege
-Status: Open
+Status: Closed
Type: Bug
Package: OpenSSL related
Operating System: Windows 10
PHP Version: 7.3.9
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
It has been explained in detail why this isn't a security
regarding PHP[1].
Please refrain from re-opening this ticket again.
Thanks.
[1] <https://bugs.php.net/78557#1568888952>
Previous Comments:
------------------------------------------------------------------------
[2019-10-09 04:56:30] zhutq2 at knownsec dot com
> Resubmit comment to open the issue. I think this is a security issue in php and need a CVE-ID.
As we all know, Openssl is an open source software library and anyone can use it. Openssl should
responsible for itself, but it is not responsible for all software that uses it.
Openssl fix the vulnerability(CVE-2019-1552) in 30 July 2019, But the openssl extention in php-src
didn't keep in sync with openssl official. So the vulnerability still effect openssl extention
until I report it. Build script and build parameters not in php-src source code but it is the base
of php-src. You can't separate them.
Curl for Windows has a similar vulnerability (CVE-2019-5443) [1][2] and I need a CVE-ID too.
1. <https://hackerone.com/reports/608577>
2. <https://curl.haxx.se/docs/CVE-2019-5443.html>
------------------------------------------------------------------------
[2019-10-08 09:05:44] zhutq2 at knownsec dot com
I revisited all previous comments, I think @cmb doesn't think this is a security issue because:
This is not related to php-src, but rather to the Windows builds of OpenSSL.
I don't think so. As we all know, Openssl is a open source software library and anyone can use
it. Openssl should responsible for itself, but it is not responsible for all software that uses it.
Openssl fix the vulnerability(CVE-2019-1552) in 30 July 2019, But the openssl extention in php-src
didn't keep in sync with openssl official. So the vulnerability still effect openssl extention
until I report it. Build script and build parameters not in php-src source code but it is the base
of php-src. You can't separate them.
Curl for Windows has a similar vulnerability (CVE-2019-5443) [1][2] and I need a CVE-ID too.
1. <https://hackerone.com/reports/608577>
2. <https://curl.haxx.se/docs/CVE-2019-5443.html>
------------------------------------------------------------------------
[2019-10-07 07:31:36] cmb@php.net
The default OpenSSL config path has been changed for PHP
7.4+[1][2], the official PHP 7.4.0RC3 Windows builds already use
this, and the docs now have a cautionary note regarding this
issue, which is not a security issue per se. Therefore I'm
(dis)closing this ticket.
[1] <https://github.com/php/php-src/blob/b142e8a4b3e82c49600edc3469d09b4febb889ee/UPGRADING#L702-L704>
[2] <http://svn.php.net/viewvc?view=revision&revision=348111>
------------------------------------------------------------------------
[2019-09-23 14:48:35] ab@php.net
D'accord with Stas' suggestion, 7.4+ and doc is sufficient.
Thanks.
------------------------------------------------------------------------
[2019-09-23 07:28:46] cmb@php.net
> I think it makes sense to change it in master/7.4 [â¦]
ACK, we should consider that. This is, however, not related to
php-src, but rather to the Windows builds of OpenSSL[1], and
changing the default path would be as simple as changing the value
of the --openssldir configure option, re-building the relevant
packages, and re-building PHP.
[1] <https://github.com/winlibs/openssl>
[2] <https://wiki.php.net/internals/windows/libs#library_dependencies>
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=78557
--
Edit this bug report at https://bugs.php.net/bug.php?id=78557&edit=1