Sec Bug->Bug #79481 [Opn]: data:// wrapper can hidden some characters
| From: | stas@php.net | Date: | Thu, 16 Apr 2020 05:50:42 +0000 |
| Subject: | Sec Bug->Bug #79481 [Opn]: data:// wrapper can hidden some characters | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-226603@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=79481&edit=1
ID: 79481
Updated by: stas@php.net
Reported by: j7ur8 at qq dot com
Summary: data:// wrapper can hidden some characters
Status: Open
-Type: Security
+Type: Bug
Package: Streams related
Operating System: Windows Linux
PHP Version: 7.4.4
Block user comment: N
Private report: Y
New Comment:
Doesn't look like there's any security issue here.
Previous Comments:
------------------------------------------------------------------------
[2020-04-16 05:47:04] j7ur8 at qq dot com
Description:
------------
From
https://www.php.net/manual/en/wrappers.data.php#refsect1-wrappers.data-description`,
i know it refer to RFC 2397. And i found it may not defined securely ?
From RFC 2397
Syntax:
dataurl := "data:" [ mediatype ] [ ";base64" ] "," data
mediatype := [ type "/" subtype ] *( ";" parameter )
data := *urlchar
parameter := attribute "=" value
and if <mediatype> is omitted, it defaults to text/plain;charset=US-ASCII. That
means we can change it freely, such as data:text/plain;charset=iso-8859-7,%be%fg%be
would use the iso-8859-7 to handle datas. But i do not think php supports it wholly which results
to characters can hide in the data wrapper stream.
Test script:
---------------
<?php
echo file_get_contents('data:,cc')."\n"; # valid
echo file_get_contents('data://asdc/asd;ccc=ccc,cc')."\n"; # with bad characters
hide in
Expected result:
----------------
cc
cc
Actual result:
--------------
cc
cc
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=79481&edit=1