Req #68599 [Asn]: exec()/passthru() function should use execv, execve
| From: | cmb@php.net | Date: | Mon, 27 Jan 2020 14:01:18 +0000 |
| Subject: | Req #68599 [Asn]: exec()/passthru() function should use execv, execve | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-225148@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=68599&edit=1
ID: 68599
Updated by: cmb@php.net
Reported by: yohgaki@php.net
Summary: exec()/passthru() function should use execv, execve
Status: Assigned
Type: Feature/Change Request
Package: Program Execution
Operating System: ANY
PHP Version: Irrelevant
Assigned To: yohgaki
Block user comment: N
Private report: N
New Comment:
For what it's worth, as of PHP 7.4.0 proc_open() also accepts an
array[1].
[1] <https://www.php.net/manual/en/migration74.new-features.php#migration74.new-features.standard.proc-open>
Previous Comments:
------------------------------------------------------------------------
[2015-02-03 07:10:32] yohgaki@php.net
@pajoye
The issue is escapeshellarg() has issues like non-ascii chars and there are too many shells. We
don't really know how to escape perfectly for all shells.
Instead of trying to escape right, we may just provide execv/execve.
I'll check proc_open() code and write patch. If it has issues on windows, please fix them :)
------------------------------------------------------------------------
[2015-01-23 05:17:17] pajoye@php.net
I am not totally sure what this request tries to change or what you ask for windows.
The changes I see here are already supported with proc_open and the likes.
On windows it does not matter much as CreateProcess is used for all these functions and has the env
parameter.
------------------------------------------------------------------------
[2015-01-23 05:12:03] pajoye@php.net
Not a security issue,remove private flag
------------------------------------------------------------------------
[2015-01-22 22:03:46] yohgaki@php.net
Stas, it's not direct security issue since user may execute commands safely with exec.
However, writing secure command with arguments is not trivial work as it seems. execv, execve is
much easier/safer than exec. It would be only master improvement. (It's security improvement,
IMHO)
If no one objects, I'll write patch. Things that I'm not sure is why pcntl is enabled only
in CLI. It's because signal handling I suppose. Is there any other reasons?
------------------------------------------------------------------------
[2014-12-30 08:29:52] stas@php.net
Not sure why is it a security issue?
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=68599
--
Edit this bug report at https://bugs.php.net/bug.php?id=68599&edit=1