Sec Bug->Bug #76362 [Ver]: Bypass open_basedir restriction via scandir and glob://
| From: | cmb@php.net | Date: | Mon, 12 Jul 2021 15:38:43 +0000 |
| Subject: | Sec Bug->Bug #76362 [Ver]: Bypass open_basedir restriction via scandir and glob:// | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-234980@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=76362&edit=1
ID: 76362
Updated by: cmb@php.net
Reported by: will at wbowling dot info
Summary: Bypass open_basedir restriction via scandir and
glob://
Status: Verified
-Type: Security
+Type: Bug
Package: *Directory/Filesystem functions
Operating System: Linux
PHP Version: 7.2.5
Block user comment: N
Private report: Y
New Comment:
open_basedir bypasses are not considered to be security issues;
cf. <https://externals.io/message/105606>
and <https://externals.io/message/115406>.
Previous Comments:
------------------------------------------------------------------------
[2021-01-05 15:07:15] cmb@php.net
Related To: Bug #80593
------------------------------------------------------------------------
[2020-05-05 15:04:58] cmb@php.net
The problem is in php_check_specific_open_basedir(). When
VCWD_REALPATH() is called[1] the first time, the path is not
resolved. In the following, path_tmp is set to an empty string[2],
and when VCWD_REALPATH() is called again with the empty string, it
resolves to the CWD, which is obviously wrong.
A simple fix would be:
main/fopen_wrappers.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/main/fopen_wrappers.c b/main/fopen_wrappers.c
index 520edfadbb..6026ba0726 100644
--- a/main/fopen_wrappers.c
+++ b/main/fopen_wrappers.c
@@ -190,7 +190,7 @@ PHPAPI int php_check_specific_open_basedir(const char *basedir, const char *path
#else
path_file = strrchr(path_tmp, DEFAULT_SLASH);
#endif
- if (!path_file) {
+ if (!path_file || path_file == path_tmp) {
/* none of the path components exist. definitely not in open_basedir.. */
return -1;
} else {
However, that would break setups where open_basedir=/
[1] <https://github.com/php/php-src/blob/php-7.2.30/main/fopen_wrappers.c#L168>
[2] <https://github.com/php/php-src/blob/php-7.2.30/main/fopen_wrappers.c#L209>
------------------------------------------------------------------------
[2018-06-25 17:49:22] cmb@php.net
Related To: Bug #76527
------------------------------------------------------------------------
[2018-05-24 15:02:23] cmb@php.net
> After a bit more testing it will only bypass the restriction if
> the current working directory is in the open_basedir:
Indeed!
------------------------------------------------------------------------
[2018-05-23 23:54:40] will at wbowling dot info
After a bit more testing it will only bypass the restriction if the current working directory is in
the open_basedir:
$ pwd
/tmp
$ php -d open_basedir=/tmp/restrict restrict/poc.php 'glob:///*'
PHP Warning: scandir(): open_basedir restriction in effect. File(/*) is not within the allowed
path(s): (/tmp/restrict) in /tmp/restrict/poc.php on line 2
...
$ cd restrict/
$ php -d open_basedir=/tmp/restrict ./poc.php 'glob:///*'
Array
(
[0] => bin
[1] => boot
...
)
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=76362
--
Edit this bug report at https://bugs.php.net/bug.php?id=76362&edit=1