Sec Bug->Bug #79635 [Opn->Sus]: mime_content_type wrong type with proper file
| From: | stas@php.net | Date: | Mon, 01 Jun 2020 18:05:45 +0000 |
| Subject: | Sec Bug->Bug #79635 [Opn->Sus]: mime_content_type wrong type with proper file | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-227265@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=79635&edit=1
ID: 79635
Updated by: stas@php.net
Reported by: matteo dot gruppi at cyberoo dot com
Summary: mime_content_type wrong type with proper file
-Status: Open
+Status: Suspended
-Type: Security
+Type: Bug
Package: Filesystem function related
Operating System: UNIX
PHP Version: Irrelevant
Block user comment: N
Private report: Y
New Comment:
mime_content_type() does not guarantee secure detection of file type (which doesn't exist
anyway - file type is just a guess, same file can be interpreted by different programs in different
ways). If you have some specific way in which the function can be improved, please suggest.
Otherwise, this is not really actionable.
Previous Comments:
------------------------------------------------------------------------
[2020-06-01 17:03:42] cmb@php.net
I don't think that erroneous results from mime_content_type() and
friends qualify as security issues. After all, these *try* to
detect the proper mimetype.
------------------------------------------------------------------------
[2020-05-26 08:24:34] matteo dot gruppi at cyberoo dot com
Description:
------------
---
From manual page: https://php.net/function.mime-content-type
---
The mime_content_type() function will return the type of file but only check the first N bytes for
the mime type.
Using the mimetype command from command line will return a different type.
The negative scenario is one in which someone creates a malicious file by injecting the first bytes
to allow the function to recognize the file as expected (for example as .pdf) but the real type of
the file is another.
Test script:
---------------
$file1="real_pdf.pdf";
$file2="real_php.pdf";
$file3="fake_pdf_with_php.pdf";
$finfo = finfo_open(FILEINFO_MIME_TYPE);
echo $file1." mime_content_type: ".mime_content_type($file1)." finfo_file:
".finfo_file($finfo, $file1)." syscall: ".system('/usr/bin/mimetype
'.$file1)."\r\n";
echo $file2." mime_content_type: ".mime_content_type($file2)." finfo_file:
".finfo_file($finfo, $file2)." syscall: ".system('/usr/bin/mimetype
'.$file2)."\r\n";
echo $file3." mime_content_type: ".mime_content_type($file3)." finfo_file:
".finfo_file($finfo, $file3)." syscall: ".system('/usr/bin/mimetype
'.$file3)."\r\n";
Expected result:
----------------
real_pdf.pdf mime_content_type: application/pdf finfo_file: application/pdf syscall: real_pdf.pdf:
application/pdf
real_php.pdf mime_content_type: text/x-php finfo_file: text/x-php syscall: real_php.pdf:
application/x-php
fake_pdf_with_php.pdf mime_content_type: application/x-php finfo_file: application/x-php syscall:
fake_pdf_with_php.pdf: application/x-php
Actual result:
--------------
real_pdf.pdf mime_content_type: application/pdf finfo_file: application/pdf syscall: real_pdf.pdf:
application/pdf
real_php.pdf mime_content_type: text/x-php finfo_file: text/x-php syscall: real_php.pdf:
application/x-php
fake_pdf_with_php.pdf mime_content_type: application/pdf finfo_file: application/pdf syscall:
fake_pdf_with_php.pdf: application/x-php
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=79635&edit=1