Req #72999 [Opn->Csd]: assert_options should allow to disable evaluation of strings in assert()

From: Date: Fri, 03 Jan 2020 09:47:16 +0000
Subject: Req #72999 [Opn->Csd]: assert_options should allow to disable evaluation of strings in assert()
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-224675@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72999&edit=1

 ID:                 72999
 Updated by:         nikic@php.net
 Reported by:        php dot bohwaz at miam dot kd2 dot org
 Summary:            assert_options should allow to disable evaluation of
                     strings in assert()
-Status:             Open
+Status:             Closed
 Type:               Feature/Change Request
 Package:            PHP options/info functions
 Operating System:   All
 PHP Version:        5.6.25
-Assigned To:        
+Assigned To:        nikic
 Block user comment: N
 Private report:     N

 New Comment:

Evaluation of strings in assert() has been deprecated in PHP 7.2 and removed in PHP 8.0, so I'm
considering this as resolved.


Previous Comments:
------------------------------------------------------------------------
[2016-09-02 02:17:51] php dot bohwaz at miam dot kd2 dot org

Description:
------------
assert() being able to evaluate its first argument if it is a string can lead to security problems,
especially on shared hosting where assertions are usually enabled by default.

This way assert() may be used as a way to execute malicious code.

A good idea for the next PHP 7 release would be to add an option to assert_options() to be able to
disable the eval() feature of assert() for strings. An example of this idea:

<?php
assert_options(ASSERT_EVAL, false);

assert('print("OK");'); // evaluated as string => true, assertion successful
?>

And on the next major PHP version we could then disable evaluation by default (BC break), and still
let users enable that if needed. This would improve default security of PHP installations.

Test script:
---------------
<?php

// Example of possible remote code execution

function getUser($id)
{
    assert($id, 'User ID is not present');
}

getUser($_GET['id']);




------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=72999&edit=1


Thread (2 messages)

« previous php.bugs (#224675) next »