Bug #75077 [Opn->Csd]: syslog messages need to be checked for conformance with RFC-3164 and RFC-5424

From: Date: Fri, 30 Jul 2021 10:52:25 +0000
Subject: Bug #75077 [Opn->Csd]: syslog messages need to be checked for conformance with RFC-3164 and RFC-5424
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-235472@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=75077&edit=1 ID: 75077 Updated by: cmb@php.net Reported by: philipp at redfish-solutions dot com Summary: syslog messages need to be checked for conformance with RFC-3164 and RFC-5424 -Status: Open +Status: Closed Type: Bug -Package: Unknown/Other Function +Package: *Network Functions Operating System: linux 4.9.40 PHP Version: 7.1.8 -Assigned To: +Assigned To: cmb Block user comment: N Private report: N New Comment: As of PHP 7.3.0, you can set syslog.filter=ascii[1] what escapes all non-printable ASCII characters. It seems to me that is sufficient to comply to these RFCs. [1] <https://www.php.net/manual/en/errorfunc.configuration.php#ini.syslog.filter> Previous Comments: ------------------------------------------------------------------------ [2017-08-16 19:16:03] philipp at redfish-solutions dot com The more I think about this, the less I think it should be a security bug since there's nothing specific to PHP that makes it the vulnerability. Can we please change this to "BUG" instead? ------------------------------------------------------------------------ [2017-08-15 20:47:21] philipp at redfish-solutions dot com Description: ------------ This issue came up in the discussions for bz #74860. Basically, the only type of message explicitly and unequivocally allowed by the Syslog RFC's is NVT ASCII (i.e. hex characters 0x20-0x7E). UTF-8 maybe used in compressed (shortest form) but it must be prefixed with a BOM (0xEF,0xBB,0xBF). Also, see the discussion for PR #2674. Test script: --------------- <?php ini_set("error_log", "syslog"); error_log("h\364pital stra\337e", 0); error_log("this string \321\032\003", 0); ?> Expected result: ---------------- It's not obvious what the correct behavior is in legacy cases which violate the RFC's. Actual result: -------------- Aug 15 14:43:07 ubuntu16 php7.0: h?pital stra?e Aug 15 14:43:07 ubuntu16 php7.0: this string ?#032#003 ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=75077&edit=1

« previous php.bugs (#235472) next »