Req #68599 [Asn]: exec()/passthru() function should use execv, execve

From: Date: Mon, 27 Jan 2020 14:01:18 +0000
Subject: Req #68599 [Asn]: exec()/passthru() function should use execv, execve
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-225148@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68599&edit=1 ID: 68599 Updated by: cmb@php.net Reported by: yohgaki@php.net Summary: exec()/passthru() function should use execv, execve Status: Assigned Type: Feature/Change Request Package: Program Execution Operating System: ANY PHP Version: Irrelevant Assigned To: yohgaki Block user comment: N Private report: N New Comment: For what it's worth, as of PHP 7.4.0 proc_open() also accepts an array[1]. [1] <https://www.php.net/manual/en/migration74.new-features.php#migration74.new-features.standard.proc-open> Previous Comments: ------------------------------------------------------------------------ [2015-02-03 07:10:32] yohgaki@php.net @pajoye The issue is escapeshellarg() has issues like non-ascii chars and there are too many shells. We don't really know how to escape perfectly for all shells. Instead of trying to escape right, we may just provide execv/execve. I'll check proc_open() code and write patch. If it has issues on windows, please fix them :) ------------------------------------------------------------------------ [2015-01-23 05:17:17] pajoye@php.net I am not totally sure what this request tries to change or what you ask for windows. The changes I see here are already supported with proc_open and the likes. On windows it does not matter much as CreateProcess is used for all these functions and has the env parameter. ------------------------------------------------------------------------ [2015-01-23 05:12:03] pajoye@php.net Not a security issue,remove private flag ------------------------------------------------------------------------ [2015-01-22 22:03:46] yohgaki@php.net Stas, it's not direct security issue since user may execute commands safely with exec. However, writing secure command with arguments is not trivial work as it seems. execv, execve is much easier/safer than exec. It would be only master improvement. (It's security improvement, IMHO) If no one objects, I'll write patch. Things that I'm not sure is why pcntl is enabled only in CLI. It's because signal handling I suppose. Is there any other reasons? ------------------------------------------------------------------------ [2014-12-30 08:29:52] stas@php.net Not sure why is it a security issue? ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=68599 -- Edit this bug report at https://bugs.php.net/bug.php?id=68599&edit=1

« previous php.bugs (#225148) next »