Bug #75077 [Opn->Csd]: syslog messages need to be checked for conformance with RFC-3164 and RFC-5424
| From: | cmb@php.net | Date: | Fri, 30 Jul 2021 10:52:25 +0000 |
| Subject: | Bug #75077 [Opn->Csd]: syslog messages need to be checked for conformance with RFC-3164 and RFC-5424 | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-235472@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=75077&edit=1
ID: 75077
Updated by: cmb@php.net
Reported by: philipp at redfish-solutions dot com
Summary: syslog messages need to be checked for conformance
with RFC-3164 and RFC-5424
-Status: Open
+Status: Closed
Type: Bug
-Package: Unknown/Other Function
+Package: *Network Functions
Operating System: linux 4.9.40
PHP Version: 7.1.8
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
As of PHP 7.3.0, you can set syslog.filter=ascii[1] what escapes
all non-printable ASCII characters. It seems to me that is
sufficient to comply to these RFCs.
[1] <https://www.php.net/manual/en/errorfunc.configuration.php#ini.syslog.filter>
Previous Comments:
------------------------------------------------------------------------
[2017-08-16 19:16:03] philipp at redfish-solutions dot com
The more I think about this, the less I think it should be a security bug since there's nothing
specific to PHP that makes it the vulnerability. Can we please change this to "BUG"
instead?
------------------------------------------------------------------------
[2017-08-15 20:47:21] philipp at redfish-solutions dot com
Description:
------------
This issue came up in the discussions for bz #74860.
Basically, the only type of message explicitly and unequivocally allowed by the Syslog RFC's is
NVT ASCII (i.e. hex characters 0x20-0x7E).
UTF-8 maybe used in compressed (shortest form) but it must be prefixed with a BOM (0xEF,0xBB,0xBF).
Also, see the discussion for PR #2674.
Test script:
---------------
<?php
ini_set("error_log", "syslog");
error_log("h\364pital stra\337e", 0);
error_log("this string \321\032\003", 0);
?>
Expected result:
----------------
It's not obvious what the correct behavior is in legacy cases which violate the RFC's.
Actual result:
--------------
Aug 15 14:43:07 ubuntu16 php7.0: h?pital stra?e
Aug 15 14:43:07 ubuntu16 php7.0: this string ?#032#003
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=75077&edit=1