Bug #81087 [Fbk->Nab]: Disabled function must not be allowed to declare in script
| From: | girgias@php.net | Date: | Thu, 27 May 2021 20:04:34 +0000 |
| Subject: | Bug #81087 [Fbk->Nab]: Disabled function must not be allowed to declare in script | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-234056@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=81087&edit=1
ID: 81087
Updated by: girgias@php.net
Reported by: mvorisek at mvorisek dot cz
Summary: Disabled function must not be allowed to declare in
script
-Status: Feedback
+Status: Not a bug
Type: Bug
Package: *General Issues
Operating System: any
PHP Version: 8.0.6
Block user comment: N
Private report: N
New Comment:
Thank you for taking the time to write to us, but this is not
a bug. Please double-check the documentation available at
http://www.php.net/manual/ and the instructions on how to
report
a bug at http://bugs.php.net/how-to-report.php
See the migration guide, this is intended behaviour:
> Disabled functions are now treated exactly like non-existent functions. Calling a > disabled
> function will report it as unknown, and redefining a disabled function is > now possible.
Previous Comments:
------------------------------------------------------------------------
[2021-05-27 17:39:09] krakjoe@php.net
*because it wants
------------------------------------------------------------------------
[2021-05-27 17:37:55] krakjoe@php.net
If a third party has the access necessary to declare a new function, isn't it too late to plug
the security hole you imagine this opens up ?
It's now a possibility for normal code to disable an inbuilt function because it wasn't to
declare another implementation, I'm not sure why we should not allow that.
------------------------------------------------------------------------
[2021-05-27 17:30:42] mvorisek at mvorisek dot cz
Description:
------------
See https://3v4l.org/DNoNp
As of PHP 8.0 disabled function are removed before the script is run.
But the function name can be redeclared in script which can imply a script security issue.
Imagine proc_open (and all related) functions are disabled. Some 3rd party can redeclare this
function. When some script checks for existence of that function, check passes and completely
different implementation is run. This should be not possible.
It is fine that function_exists returns false for disabled function, but injecting function with the
same name must result in a fatal error.
Test script:
---------------
<?php
var_dump(ini_get('disable_functions')); // string(22) "proc_open,phpinfo,mail"
eval('function proc_open() { echo \'x\'; }');
proc_open();
Expected result:
----------------
see desc, fatal error
Actual result:
--------------
string(22) "proc_open,phpinfo,mail"
x
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=81087&edit=1