Bug #77496 [Com]: mysqli->real_connect() overwrites MYSQLI_OPT_LOCAL_INFILE setting
| From: | greenreaper at hotmail dot com | Date: | Thu, 13 Feb 2020 02:50:01 +0000 |
| Subject: | Bug #77496 [Com]: mysqli->real_connect() overwrites MYSQLI_OPT_LOCAL_INFILE setting | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-225549@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77496&edit=1
ID: 77496
Comment by: greenreaper at hotmail dot com
Reported by: php at yghe dot net
Summary: mysqli->real_connect() overwrites
MYSQLI_OPT_LOCAL_INFILE setting
Status: Verified
Type: Bug
Package: MySQLi related
Operating System: Mac OS X Mojave 10.14.2
PHP Version: 7.3.1
Block user comment: N
Private report: N
New Comment:
On a related note, it's confusing that the commented-out configuration line for
mysqli.allow_local_infile in the production ini makes it look like the default is still
'On', when in fact it's 'Off':
https://github.com/php/php-src/blob/master/php.ini-production#L1131
Perhaps this was missed when disabling it in 7.2.16 and 7.3.3? Other commented-out items tend to use
the default value, or even explicitly state the default as well as the production value.
Previous Comments:
------------------------------------------------------------------------
[2019-01-23 10:56:25] hanno at hboeck dot de
> ...in the application. Not in PHP. There's a distinction there often lost in the
> commentary on this bug tracker.
No, sorry, it's not. The application tries to set a security related flag with PHP. It should
work. It does not.
phpmyadmin added a workaround for a PHP bug. It's still a PHP bug causing a security issue.
------------------------------------------------------------------------
[2019-01-23 10:32:55] spam2 at rhsoft dot net
>> I'd like to point out that this actually is a security issue.
> ...in the application
this arrogance when MYSQLI_OPT_LOCAL_INFILE in the application should prevent issues like https://gwillem.gitlab.io/2019/01/17/adminer-4.6.2-file-disclosure-vulnerability/
------------------------------------------------------------------------
[2019-01-22 17:10:17] spam2 at rhsoft dot net
the distinction in this bugtracker is more than questionable and how security relevant bad behavior
is treated is terrible at all and has a broader impact:
distributions which are doing only backports of security bugfixes when everything is handeled
"it's not a security bug"
this general attitude is part of PHP's bad reputation
------------------------------------------------------------------------
[2019-01-22 16:58:31] requinix@php.net
> I'd like to point out that this actually is a security issue.
...in the application. Not in PHP. There's a distinction there often lost in the commentary on
this bug tracker.
------------------------------------------------------------------------
[2019-01-22 11:17:08] hanno at hboeck dot de
I'd like to point out that this actually is a security issue.
LOCAL INFILE can be used by a malicious server to exfiltrate files from the client. Disabling this
option thus can certainly have security implications.
This caused an issue in phpmyadmin where they thought they set that option, but it wasn't
active:
https://github.com/phpmyadmin/phpmyadmin/commit/c5e01f84ad48c5c626001cb92d7a95500920a900
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=77496
--
Edit this bug report at https://bugs.php.net/bug.php?id=77496&edit=1