Sec Bug->Bug #80901 [Opn]: Info leak in ftp extension

From: Date: Wed, 14 Apr 2021 06:00:49 +0000
Subject: Sec Bug->Bug #80901 [Opn]: Info leak in ftp extension
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-233416@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80901&edit=1

 ID:                 80901
 Updated by:         stas@php.net
 Reported by:        zengyhkyle at asu dot edu
 Summary:            Info leak in ftp extension
 Status:             Open
-Type:               Security
+Type:               Bug
 Package:            FTP related
 Operating System:   Linux
 PHP Version:        8.0.4RC1
 Block user comment: N
 Private report:     Y

 New Comment:

Let's fix it in 7.4+


Previous Comments:
------------------------------------------------------------------------
[2021-04-13 10:15:20] cmb@php.net

> The attack is not remote. It is for sandbox escape.

I don't think that we classify such issues as security issues.
Otherwise our security classification[1] wouldn't make much sense.

So how to proceed?  This is basically a duplicate of bug #79100,
and a suggested fix[2] is waiting for review.

[1] <https://wiki.php.net/security>
[2] <https://github.com/php/php-src/pull/6718>

------------------------------------------------------------------------
[2021-03-30 19:22:24] zengyhkyle at asu dot edu

The attack is not remote. It is for sandbox escape.
There are many sandboxed PHP runtime environments online for public use. An attacker can use this
vulnerability to leak pointers by using the FTP functionality. If combined with another
vulnerability, the attacker is able to escape from the sandbox and executes code on the server that
runs the sandboxed php.

------------------------------------------------------------------------
[2021-03-29 04:12:46] stas@php.net

But the attacker does not get the information that is in the warning, so where's the attack? I
am still not sure how the attack scenario would work. Say I set up a special FTP server, then trick
somebody to connect to it, then what? I still can't see anything that happens on their end...

------------------------------------------------------------------------
[2021-03-27 18:46:13] zengyhkyle at asu dot edu

yes. the pointer leaked is the client.
The exploit requires the client to receive a special message from a server, which can be done by
communicating a server owned by the attacker.

------------------------------------------------------------------------
[2021-03-24 10:13:36] cmb@php.net

On a quick glance, it seems that would be fixed by
<https://github.com/php/php-src/pull/6718>.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=80901


--
Edit this bug report at https://bugs.php.net/bug.php?id=80901&edit=1


Thread (1 message)

  • stas@php.net
  • Unknown Message
    • stas@php.net
« previous php.bugs (#233416) next »