Bug #81087 [Fbk->Nab]: Disabled function must not be allowed to declare in script

From: Date: Thu, 27 May 2021 20:04:34 +0000
Subject: Bug #81087 [Fbk->Nab]: Disabled function must not be allowed to declare in script
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-234056@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81087&edit=1 ID: 81087 Updated by: girgias@php.net Reported by: mvorisek at mvorisek dot cz Summary: Disabled function must not be allowed to declare in script -Status: Feedback +Status: Not a bug Type: Bug Package: *General Issues Operating System: any PHP Version: 8.0.6 Block user comment: N Private report: N New Comment: Thank you for taking the time to write to us, but this is not a bug. Please double-check the documentation available at http://www.php.net/manual/ and the instructions on how to report a bug at http://bugs.php.net/how-to-report.php See the migration guide, this is intended behaviour: > Disabled functions are now treated exactly like non-existent functions. Calling a > disabled > function will report it as unknown, and redefining a disabled function is > now possible. Previous Comments: ------------------------------------------------------------------------ [2021-05-27 17:39:09] krakjoe@php.net *because it wants ------------------------------------------------------------------------ [2021-05-27 17:37:55] krakjoe@php.net If a third party has the access necessary to declare a new function, isn't it too late to plug the security hole you imagine this opens up ? It's now a possibility for normal code to disable an inbuilt function because it wasn't to declare another implementation, I'm not sure why we should not allow that. ------------------------------------------------------------------------ [2021-05-27 17:30:42] mvorisek at mvorisek dot cz Description: ------------ See https://3v4l.org/DNoNp As of PHP 8.0 disabled function are removed before the script is run. But the function name can be redeclared in script which can imply a script security issue. Imagine proc_open (and all related) functions are disabled. Some 3rd party can redeclare this function. When some script checks for existence of that function, check passes and completely different implementation is run. This should be not possible. It is fine that function_exists returns false for disabled function, but injecting function with the same name must result in a fatal error. Test script: --------------- <?php var_dump(ini_get('disable_functions')); // string(22) "proc_open,phpinfo,mail" eval('function proc_open() { echo \'x\'; }'); proc_open(); Expected result: ---------------- see desc, fatal error Actual result: -------------- string(22) "proc_open,phpinfo,mail" x ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=81087&edit=1

« previous php.bugs (#234056) next »