Bug #80901 [PATCH]: Info leak in ftp extension
| From: | cmb@php.net | Date: | Thu, 22 Apr 2021 12:16:20 +0000 |
| Subject: | Bug #80901 [PATCH]: Info leak in ftp extension | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-233555@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=80901&edit=1
ID: 80901
Patch added by: cmb@php.net
Reported by: zengyhkyle at asu dot edu
Summary: Info leak in ftp extension
Status: Verified
Type: Bug
Package: FTP related
Operating System: Linux
PHP Version: 7.4
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
The following pull request has been associated:
Patch Name: Fix #80901: Info leak in ftp extension
On GitHub: https://github.com/php/php-src/pull/6894
Patch: https://github.com/php/php-src/pull/6894.patch
Previous Comments:
------------------------------------------------------------------------
[2021-04-21 16:23:38] cmb@php.net
Correction: this is not related to endianess, but rather to struct
member alignment, so would affect Windows x86 builds, for
instance.
------------------------------------------------------------------------
[2021-04-21 15:23:36] cmb@php.net
Oh, no, this is not related to bug #79100 at all. I had a very
hard time to reproduce this, and finally found that it likely
cannot be triggered on a little-endian machine, since the struct
has a char* immediately after the inbuf, and its high byte is
likely zero, so actually there is no buffer overflow (furthermore,
prior to PHP 8.0.0, log_errors_max_len likely caused truncation of
the output anyway, so no buffer overflow would happen). On
big-endian machines the outcome is likely different.
------------------------------------------------------------------------
[2021-04-14 06:00:49] stas@php.net
Let's fix it in 7.4+
------------------------------------------------------------------------
[2021-04-13 10:15:20] cmb@php.net
> The attack is not remote. It is for sandbox escape.
I don't think that we classify such issues as security issues.
Otherwise our security classification[1] wouldn't make much sense.
So how to proceed? This is basically a duplicate of bug #79100,
and a suggested fix[2] is waiting for review.
[1] <https://wiki.php.net/security>
[2] <https://github.com/php/php-src/pull/6718>
------------------------------------------------------------------------
[2021-03-30 19:22:24] zengyhkyle at asu dot edu
The attack is not remote. It is for sandbox escape.
There are many sandboxed PHP runtime environments online for public use. An attacker can use this
vulnerability to leak pointers by using the FTP functionality. If combined with another
vulnerability, the attacker is able to escape from the sandbox and executes code on the server that
runs the sandboxed php.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=80901
--
Edit this bug report at https://bugs.php.net/bug.php?id=80901&edit=1