Bug #80901 [Ver->Csd]: Info leak in ftp extension

From: Date: Mon, 26 Apr 2021 12:47:34 +0000
Subject: Bug #80901 [Ver->Csd]: Info leak in ftp extension
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-233574@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80901&edit=1

 ID:                 80901
 Updated by:         git@php.net
 Reported by:        zengyhkyle at asu dot edu
 Summary:            Info leak in ftp extension
-Status:             Verified
+Status:             Closed
 Type:               Bug
 Package:            FTP related
 Operating System:   Linux
 PHP Version:        7.4
 Assigned To:        cmb
 Block user comment: N
 Private report:     N

 New Comment:

Automatic comment on behalf of cmb69
Revision: https://github.com/php/php-src/commit/09696eee9d4374e79bd443bbbd5c5d38bfb9fb68
Log: Fix #80901: Info leak in ftp extension


Previous Comments:
------------------------------------------------------------------------
[2021-04-22 12:16:20] cmb@php.net

The following pull request has been associated:

Patch Name: Fix #80901: Info leak in ftp extension
On GitHub:  https://github.com/php/php-src/pull/6894
Patch:      https://github.com/php/php-src/pull/6894.patch

------------------------------------------------------------------------
[2021-04-21 16:23:38] cmb@php.net

Correction: this is not related to endianess, but rather to struct
member alignment, so would affect Windows x86 builds, for
instance.

------------------------------------------------------------------------
[2021-04-21 15:23:36] cmb@php.net

Oh, no, this is not related to bug #79100 at all.  I had a very
hard time to reproduce this, and finally found that it likely
cannot be triggered on a little-endian machine, since the struct
has a char* immediately after the inbuf, and its high byte is
likely zero, so actually there is no buffer overflow (furthermore,
prior to PHP 8.0.0, log_errors_max_len likely caused truncation of
the output anyway, so no buffer overflow would happen).  On
big-endian machines the outcome is likely different.

------------------------------------------------------------------------
[2021-04-14 06:00:49] stas@php.net

Let's fix it in 7.4+

------------------------------------------------------------------------
[2021-04-13 10:15:20] cmb@php.net

> The attack is not remote. It is for sandbox escape.

I don't think that we classify such issues as security issues.
Otherwise our security classification[1] wouldn't make much sense.

So how to proceed?  This is basically a duplicate of bug #79100,
and a suggested fix[2] is waiting for review.

[1] <https://wiki.php.net/security>
[2] <https://github.com/php/php-src/pull/6718>

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=80901


--
Edit this bug report at https://bugs.php.net/bug.php?id=80901&edit=1


Thread (1 message)

  • git@php.net
  • Unknown Message
    • git@php.net
« previous php.bugs (#233574) next »