Sec Bug->Bug #78861 [Nab]: [DoS] Segmentation fault through HTTP Requests by string strip_tags

From: Date: Mon, 16 Dec 2019 14:13:48 +0000
Subject: Sec Bug->Bug #78861 [Nab]: [DoS] Segmentation fault through HTTP Requests by string strip_tags
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-224342@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78861&edit=1 ID: 78861 Updated by: cmb@php.net Reported by: jessica1123 at yeah dot net Summary: [DoS] Segmentation fault through HTTP Requests by string strip_tags Status: Not a bug -Type: Security +Type: Bug Package: *Web Server problem Operating System: Ubuntu 16.04 PHP Version: 7.1.33 Assigned To: cmb Block user comment: N Private report: Y New Comment: To clarify: the supplied test script is badly written, and as such is vulnerable to RCI attacks. This is not related to any bug in PHP. Please refrain from categorizing this issue as security bug, which it is not. Thanks. Previous Comments: ------------------------------------------------------------------------ [2019-12-16 14:01:31] jessica1123 at yeah dot net I would be happy to help you fix this. But if you don't plan to fix this problem, I hope you can help me apply for CVE, I will be very grateful to you. ------------------------------------------------------------------------ [2019-12-13 15:01:11] cmb@php.net Well, thanks to Remi, I had a closer look at this issue, and the given script is vulnerable to RCI anyway (unrelated to the segfault which may happen on older PHP versions), because the name of the file to be written to is not validated. ------------------------------------------------------------------------ [2019-12-06 13:24:02] jessica1123 at yeah dot net It actually affects other web servers, such as php-fpm. But since you no longer maintain php7.0, there is nothing you need to do . ------------------------------------------------------------------------ [2019-12-01 04:22:08] php-bugs at lists dot php dot net No feedback was provided. The bug is being suspended because we assume that you are no longer experiencing the problem. If this is not the case and you are able to provide the information that was requested earlier, please do so and change the status of the bug back to "Re-Opened". Thank you. ------------------------------------------------------------------------ [2019-11-23 09:17:22] cmb@php.net > I found a vulnerability while I was testing the PHP built-in web > server. Since the built-in Web server should not be used on a public network[1], security concerns do not apply. Or can this be reproduced with other Web servers as well? > My environment is php 7.0.33 , but the problem doesn't work on > 7.1.33 We do no longer support PHP 7.0; if PHP 7.1 and higher are not affected by this issue, this would not even be a bug for php.net. [1] <https://www.php.net/manual/en/features.commandline.webserver.php> ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=78861 -- Edit this bug report at https://bugs.php.net/bug.php?id=78861&edit=1

« previous php.bugs (#224342) next »