Bug #80901 [Opn->Ver]: Info leak in ftp extension

From: Date: Wed, 21 Apr 2021 15:23:36 +0000
Subject: Bug #80901 [Opn->Ver]: Info leak in ftp extension
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-233544@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80901&edit=1 ID: 80901 Updated by: cmb@php.net Reported by: zengyhkyle at asu dot edu Summary: Info leak in ftp extension -Status: Open +Status: Verified Type: Bug Package: FTP related Operating System: Linux -PHP Version: 8.0.4RC1 +PHP Version: 7.4 -Assigned To: +Assigned To: cmb Block user comment: N Private report: N New Comment: Oh, no, this is not related to bug #79100 at all. I had a very hard time to reproduce this, and finally found that it likely cannot be triggered on a little-endian machine, since the struct has a char* immediately after the inbuf, and its high byte is likely zero, so actually there is no buffer overflow (furthermore, prior to PHP 8.0.0, log_errors_max_len likely caused truncation of the output anyway, so no buffer overflow would happen). On big-endian machines the outcome is likely different. Previous Comments: ------------------------------------------------------------------------ [2021-04-14 06:00:49] stas@php.net Let's fix it in 7.4+ ------------------------------------------------------------------------ [2021-04-13 10:15:20] cmb@php.net > The attack is not remote. It is for sandbox escape. I don't think that we classify such issues as security issues. Otherwise our security classification[1] wouldn't make much sense. So how to proceed? This is basically a duplicate of bug #79100, and a suggested fix[2] is waiting for review. [1] <https://wiki.php.net/security> [2] <https://github.com/php/php-src/pull/6718> ------------------------------------------------------------------------ [2021-03-30 19:22:24] zengyhkyle at asu dot edu The attack is not remote. It is for sandbox escape. There are many sandboxed PHP runtime environments online for public use. An attacker can use this vulnerability to leak pointers by using the FTP functionality. If combined with another vulnerability, the attacker is able to escape from the sandbox and executes code on the server that runs the sandboxed php. ------------------------------------------------------------------------ [2021-03-29 04:12:46] stas@php.net But the attacker does not get the information that is in the warning, so where's the attack? I am still not sure how the attack scenario would work. Say I set up a special FTP server, then trick somebody to connect to it, then what? I still can't see anything that happens on their end... ------------------------------------------------------------------------ [2021-03-27 18:46:13] zengyhkyle at asu dot edu yes. the pointer leaked is the client. The exploit requires the client to receive a special message from a server, which can be done by communicating a server owned by the attacker. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=80901 -- Edit this bug report at https://bugs.php.net/bug.php?id=80901&edit=1

« previous php.bugs (#233544) next »