Req #64439 [Opn->Csd]: \0 causes error_log strings to be truncated

From: Date: Mon, 19 Jul 2021 14:00:16 +0000
Subject: Req #64439 [Opn->Csd]: \0 causes error_log strings to be truncated
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-235184@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=64439&edit=1 ID: 64439 Updated by: cmb@php.net Reported by: eric at wepay dot com Summary: \0 causes error_log strings to be truncated -Status: Open +Status: Closed Type: Feature/Change Request Package: *General Issues Operating System: CentOS PHP Version: 5.4.13 -Assigned To: +Assigned To: cmb Block user comment: N Private report: N New Comment: This issue is fixed as of PHP 8.1.0[1]. Note that syslog.filter[2] already allows to escape characters as of PHP 7.3.0. [1] <https://github.com/php/php-src/pull/7245> Previous Comments: ------------------------------------------------------------------------ [2016-09-04 14:22:31] yonelceruto at gmail dot com I've faced with this issue too, so my question is: Why "\0" character is dumped when private or protected properties are serialized ? It is needed for unserialize process? ------------------------------------------------------------------------ [2013-11-01 06:34:39] yohgaki@php.net Thanks for the info, but I knew this kind of attack can be done. Anyway, even if we made logging binary safe, there would be other problems. We cannot simply escape special chars because it may broke log analyzers. It's possible escape special chars, but it would not happen in released version. There is developer working on this issue. Changed bug type. ------------------------------------------------------------------------ [2013-10-30 00:42:10] spam2 at rhsoft dot net this is also *security relevant* simply strip or escape control chars and you are done study the mod_security code, they know how to escape log lines http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-1862 ------------------------------------------------------------------------ [2013-10-24 05:30:10] yohgaki@php.net Automatic comment from SVN on behalf of yohgaki Revision: http://svn.php.net/viewvc/?view=revision&amp;revision=331939 Log: Fixed Doc Bug #64439 \0 causes error_log strings to be truncated ------------------------------------------------------------------------ [2013-10-24 05:28:11] yohgaki@php.net This should be documented. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=64439 -- Edit this bug report at https://bugs.php.net/bug.php?id=64439&edit=1

« previous php.bugs (#235184) next »