Req #64439 [Opn->Csd]: \0 causes error_log strings to be truncated
| From: | cmb@php.net | Date: | Mon, 19 Jul 2021 14:00:16 +0000 |
| Subject: | Req #64439 [Opn->Csd]: \0 causes error_log strings to be truncated | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-235184@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=64439&edit=1
ID: 64439
Updated by: cmb@php.net
Reported by: eric at wepay dot com
Summary: \0 causes error_log strings to be truncated
-Status: Open
+Status: Closed
Type: Feature/Change Request
Package: *General Issues
Operating System: CentOS
PHP Version: 5.4.13
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
This issue is fixed as of PHP 8.1.0[1]. Note that
syslog.filter[2] already allows to escape characters as of PHP
7.3.0.
[1] <https://github.com/php/php-src/pull/7245>
Previous Comments:
------------------------------------------------------------------------
[2016-09-04 14:22:31] yonelceruto at gmail dot com
I've faced with this issue too, so my question is: Why "\0" character is dumped when
private or protected properties are serialized ? It is needed for unserialize process?
------------------------------------------------------------------------
[2013-11-01 06:34:39] yohgaki@php.net
Thanks for the info, but I knew this kind of attack can be done.
Anyway, even if we made logging binary safe, there would be other problems. We cannot simply escape
special chars because it may broke log analyzers. It's possible escape special chars, but it
would not happen in released version.
There is developer working on this issue. Changed bug type.
------------------------------------------------------------------------
[2013-10-30 00:42:10] spam2 at rhsoft dot net
this is also *security relevant*
simply strip or escape control chars and you are done
study the mod_security code, they know how to escape log lines
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-1862
------------------------------------------------------------------------
[2013-10-24 05:30:10] yohgaki@php.net
Automatic comment from SVN on behalf of yohgaki
Revision: http://svn.php.net/viewvc/?view=revision&revision=331939
Log: Fixed Doc Bug #64439 \0 causes error_log strings to be truncated
------------------------------------------------------------------------
[2013-10-24 05:28:11] yohgaki@php.net
This should be documented.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=64439
--
Edit this bug report at https://bugs.php.net/bug.php?id=64439&edit=1