Bug #76929 [PATCH]: zip-based phar does not respect phar.require_hash

From: Date: Wed, 16 Dec 2020 11:41:57 +0000
Subject: Bug #76929 [PATCH]: zip-based phar does not respect phar.require_hash
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-231119@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76929&edit=1 ID: 76929 Patch added by: cmb@php.net Reported by: david at bamsoftware dot com Summary: zip-based phar does not respect phar.require_hash Status: Verified Type: Bug Package: PHAR related Operating System: Linux 4.18.0-1-amd64 PHP Version: master-Git-2018-09-24 (Git) Assigned To: cmb Block user comment: N Private report: N New Comment: The following pull request has been associated: Patch Name: Fix #76929: zip-based phar does not respect phar.require_hash On GitHub: https://github.com/php/php-src/pull/6517 Patch: https://github.com/php/php-src/pull/6517.patch Previous Comments: ------------------------------------------------------------------------ [2020-12-16 11:40:57] cmb@php.net Good work! Unfortunately, that appears to have been overlooked. ------------------------------------------------------------------------ [2018-09-24 19:56:51] david at bamsoftware dot com Description: ------------ Phar files in the zip format do not raise an error when phar.require_hash is true and the file lacks a signature (.phar/signature.bin), unlike the phar and tar formats. The attached patch adds a test, copied with adjustments from ext/phar/tests/tar/require_hash.phpt; and a check for require_hash, copied with adjustments from ext/phar/tar.c. This bug could allow you to bypass the signature check on openssl-signed phars by rewriting them as zip files without a signature. I didn't mark the bug "Security" though, because you can accomplish the same thing more easily by rewriting the phar with e.g. an md5 signature. commit 152dc924c565330619a90f99dc1f223bb22ac420 ./configure --with-openssl --with-zlib --with-bz2 --enable-zip Test script: --------------- <? $zip = new ZipArchive; $zip->open('zip.phar', ZIPARCHIVE::CREATE); $zip->addFromString('zip.php', '<?php var_dump(__FILE__);'); $zip->addFromString('.phar/stub.php', '__HALT_COMPILER();'); $zip->close(); $phar = new Phar('zip.phar'); echo $phar->getStub(); Expected result: ---------------- Fatal error: Uncaught UnexpectedValueException: zip-based phar "zip.phar" does not have a signature in zip.php:8 Actual result: -------------- __HALT_COMPILER(); ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=76929&edit=1

« previous php.bugs (#231119) next »