Sec Bug->Bug #79635 [Opn->Sus]: mime_content_type wrong type with proper file

From: Date: Mon, 01 Jun 2020 18:05:45 +0000
Subject: Sec Bug->Bug #79635 [Opn->Sus]: mime_content_type wrong type with proper file
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-227265@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=79635&edit=1 ID: 79635 Updated by: stas@php.net Reported by: matteo dot gruppi at cyberoo dot com Summary: mime_content_type wrong type with proper file -Status: Open +Status: Suspended -Type: Security +Type: Bug Package: Filesystem function related Operating System: UNIX PHP Version: Irrelevant Block user comment: N Private report: Y New Comment: mime_content_type() does not guarantee secure detection of file type (which doesn't exist anyway - file type is just a guess, same file can be interpreted by different programs in different ways). If you have some specific way in which the function can be improved, please suggest. Otherwise, this is not really actionable. Previous Comments: ------------------------------------------------------------------------ [2020-06-01 17:03:42] cmb@php.net I don't think that erroneous results from mime_content_type() and friends qualify as security issues. After all, these *try* to detect the proper mimetype. ------------------------------------------------------------------------ [2020-05-26 08:24:34] matteo dot gruppi at cyberoo dot com Description: ------------ --- From manual page: https://php.net/function.mime-content-type --- The mime_content_type() function will return the type of file but only check the first N bytes for the mime type. Using the mimetype command from command line will return a different type. The negative scenario is one in which someone creates a malicious file by injecting the first bytes to allow the function to recognize the file as expected (for example as .pdf) but the real type of the file is another. Test script: --------------- $file1="real_pdf.pdf"; $file2="real_php.pdf"; $file3="fake_pdf_with_php.pdf"; $finfo = finfo_open(FILEINFO_MIME_TYPE); echo $file1." mime_content_type: ".mime_content_type($file1)." finfo_file: ".finfo_file($finfo, $file1)." syscall: ".system('/usr/bin/mimetype '.$file1)."\r\n"; echo $file2." mime_content_type: ".mime_content_type($file2)." finfo_file: ".finfo_file($finfo, $file2)." syscall: ".system('/usr/bin/mimetype '.$file2)."\r\n"; echo $file3." mime_content_type: ".mime_content_type($file3)." finfo_file: ".finfo_file($finfo, $file3)." syscall: ".system('/usr/bin/mimetype '.$file3)."\r\n"; Expected result: ---------------- real_pdf.pdf mime_content_type: application/pdf finfo_file: application/pdf syscall: real_pdf.pdf: application/pdf real_php.pdf mime_content_type: text/x-php finfo_file: text/x-php syscall: real_php.pdf: application/x-php fake_pdf_with_php.pdf mime_content_type: application/x-php finfo_file: application/x-php syscall: fake_pdf_with_php.pdf: application/x-php Actual result: -------------- real_pdf.pdf mime_content_type: application/pdf finfo_file: application/pdf syscall: real_pdf.pdf: application/pdf real_php.pdf mime_content_type: text/x-php finfo_file: text/x-php syscall: real_php.pdf: application/x-php fake_pdf_with_php.pdf mime_content_type: application/pdf finfo_file: application/pdf syscall: fake_pdf_with_php.pdf: application/x-php ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=79635&edit=1

« previous php.bugs (#227265) next »