Sec Bug->Bug #78861 [Nab]: [DoS] Segmentation fault through HTTP Requests by string strip_tags
| From: | cmb@php.net | Date: | Mon, 16 Dec 2019 14:13:48 +0000 |
| Subject: | Sec Bug->Bug #78861 [Nab]: [DoS] Segmentation fault through HTTP Requests by string strip_tags | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-224342@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78861&edit=1
ID: 78861
Updated by: cmb@php.net
Reported by: jessica1123 at yeah dot net
Summary: [DoS] Segmentation fault through HTTP Requests by
string strip_tags
Status: Not a bug
-Type: Security
+Type: Bug
Package: *Web Server problem
Operating System: Ubuntu 16.04
PHP Version: 7.1.33
Assigned To: cmb
Block user comment: N
Private report: Y
New Comment:
To clarify: the supplied test script is badly written, and as such
is vulnerable to RCI attacks. This is not related to any bug in
PHP.
Please refrain from categorizing this issue as security bug, which
it is not.
Thanks.
Previous Comments:
------------------------------------------------------------------------
[2019-12-16 14:01:31] jessica1123 at yeah dot net
I would be happy to help you fix this. But if you don't plan to fix this problem, I hope you
can help me apply for CVE, I will be very grateful to you.
------------------------------------------------------------------------
[2019-12-13 15:01:11] cmb@php.net
Well, thanks to Remi, I had a closer look at this issue, and the
given script is vulnerable to RCI anyway (unrelated to the
segfault which may happen on older PHP versions), because the name
of the file to be written to is not validated.
------------------------------------------------------------------------
[2019-12-06 13:24:02] jessica1123 at yeah dot net
It actually affects other web servers, such as php-fpm. But since you no longer maintain php7.0,
there is nothing you need to do .
------------------------------------------------------------------------
[2019-12-01 04:22:08] php-bugs at lists dot php dot net
No feedback was provided. The bug is being suspended because
we assume that you are no longer experiencing the problem.
If this is not the case and you are able to provide the
information that was requested earlier, please do so and
change the status of the bug back to "Re-Opened". Thank you.
------------------------------------------------------------------------
[2019-11-23 09:17:22] cmb@php.net
> I found a vulnerability while I was testing the PHP built-in web
> server.
Since the built-in Web server should not be used on a public
network[1], security concerns do not apply.
Or can this be reproduced with other Web servers as well?
> My environment is php 7.0.33 , but the problem doesn't work on
> 7.1.33
We do no longer support PHP 7.0; if PHP 7.1 and higher are not
affected by this issue, this would not even be a bug for php.net.
[1] <https://www.php.net/manual/en/features.commandline.webserver.php>
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=78861
--
Edit this bug report at https://bugs.php.net/bug.php?id=78861&edit=1