Edit report at https://bugs.php.net/bug.php?id=80901&edit=1
ID: 80901
Updated by: git@php.net
Reported by: zengyhkyle at asu dot edu
Summary: Info leak in ftp extension
-Status: Verified
+Status: Closed
Type: Bug
Package: FTP related
Operating System: Linux
PHP Version: 7.4
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of cmb69
Revision: https://github.com/php/php-src/commit/09696eee9d4374e79bd443bbbd5c5d38bfb9fb68
Log: Fix #80901: Info leak in ftp extension
Previous Comments:
------------------------------------------------------------------------
[2021-04-22 12:16:20] cmb@php.net
The following pull request has been associated:
Patch Name: Fix #80901: Info leak in ftp extension
On GitHub: https://github.com/php/php-src/pull/6894
Patch: https://github.com/php/php-src/pull/6894.patch
------------------------------------------------------------------------
[2021-04-21 16:23:38] cmb@php.net
Correction: this is not related to endianess, but rather to struct
member alignment, so would affect Windows x86 builds, for
instance.
------------------------------------------------------------------------
[2021-04-21 15:23:36] cmb@php.net
Oh, no, this is not related to bug #79100 at all. I had a very
hard time to reproduce this, and finally found that it likely
cannot be triggered on a little-endian machine, since the struct
has a char* immediately after the inbuf, and its high byte is
likely zero, so actually there is no buffer overflow (furthermore,
prior to PHP 8.0.0, log_errors_max_len likely caused truncation of
the output anyway, so no buffer overflow would happen). On
big-endian machines the outcome is likely different.
------------------------------------------------------------------------
[2021-04-14 06:00:49] stas@php.net
Let's fix it in 7.4+
------------------------------------------------------------------------
[2021-04-13 10:15:20] cmb@php.net
> The attack is not remote. It is for sandbox escape.
I don't think that we classify such issues as security issues.
Otherwise our security classification[1] wouldn't make much sense.
So how to proceed? This is basically a duplicate of bug #79100,
and a suggested fix[2] is waiting for review.
[1] <https://wiki.php.net/security>
[2] <https://github.com/php/php-src/pull/6718>
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=80901
--
Edit this bug report at https://bugs.php.net/bug.php?id=80901&edit=1