Sec Bug->Bug #76362 [Ver]: Bypass open_basedir restriction via scandir and glob://

From: Date: Mon, 12 Jul 2021 15:38:43 +0000
Subject: Sec Bug->Bug #76362 [Ver]: Bypass open_basedir restriction via scandir and glob://
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-234980@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76362&edit=1 ID: 76362 Updated by: cmb@php.net Reported by: will at wbowling dot info Summary: Bypass open_basedir restriction via scandir and glob:// Status: Verified -Type: Security +Type: Bug Package: *Directory/Filesystem functions Operating System: Linux PHP Version: 7.2.5 Block user comment: N Private report: Y New Comment: open_basedir bypasses are not considered to be security issues; cf. <https://externals.io/message/105606> and <https://externals.io/message/115406>. Previous Comments: ------------------------------------------------------------------------ [2021-01-05 15:07:15] cmb@php.net Related To: Bug #80593 ------------------------------------------------------------------------ [2020-05-05 15:04:58] cmb@php.net The problem is in php_check_specific_open_basedir(). When VCWD_REALPATH() is called[1] the first time, the path is not resolved. In the following, path_tmp is set to an empty string[2], and when VCWD_REALPATH() is called again with the empty string, it resolves to the CWD, which is obviously wrong. A simple fix would be: main/fopen_wrappers.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/main/fopen_wrappers.c b/main/fopen_wrappers.c index 520edfadbb..6026ba0726 100644 --- a/main/fopen_wrappers.c +++ b/main/fopen_wrappers.c @@ -190,7 +190,7 @@ PHPAPI int php_check_specific_open_basedir(const char *basedir, const char *path #else path_file = strrchr(path_tmp, DEFAULT_SLASH); #endif - if (!path_file) { + if (!path_file || path_file == path_tmp) { /* none of the path components exist. definitely not in open_basedir.. */ return -1; } else { However, that would break setups where open_basedir=/ [1] <https://github.com/php/php-src/blob/php-7.2.30/main/fopen_wrappers.c#L168> [2] <https://github.com/php/php-src/blob/php-7.2.30/main/fopen_wrappers.c#L209> ------------------------------------------------------------------------ [2018-06-25 17:49:22] cmb@php.net Related To: Bug #76527 ------------------------------------------------------------------------ [2018-05-24 15:02:23] cmb@php.net > After a bit more testing it will only bypass the restriction if > the current working directory is in the open_basedir: Indeed! ------------------------------------------------------------------------ [2018-05-23 23:54:40] will at wbowling dot info After a bit more testing it will only bypass the restriction if the current working directory is in the open_basedir: $ pwd /tmp $ php -d open_basedir=/tmp/restrict restrict/poc.php 'glob:///*' PHP Warning: scandir(): open_basedir restriction in effect. File(/*) is not within the allowed path(s): (/tmp/restrict) in /tmp/restrict/poc.php on line 2 ... $ cd restrict/ $ php -d open_basedir=/tmp/restrict ./poc.php 'glob:///*' Array ( [0] => bin [1] => boot ... ) ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=76362 -- Edit this bug report at https://bugs.php.net/bug.php?id=76362&edit=1

« previous php.bugs (#234980) next »