Bug #75889 [Csd]: Overloading disk with temporary files
| From: | bukka@php.net | Date: | Fri, 03 Feb 2023 14:14:14 +0000 |
| Subject: | Bug #75889 [Csd]: Overloading disk with temporary files | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-243631@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=75889&edit=1
ID: 75889
Updated by: bukka@php.net
Reported by: c dot r dot l dot f at yandex dot ru
Summary: Overloading disk with temporary files
Status: Closed
Type: Bug
Package: FPM related
Operating System: Linux
PHP Version: 7.1.13
Assigned To: bukka
Block user comment: N
Private report: N
New Comment:
I should also note that the fix is available from PHP 8.0.24
Previous Comments:
------------------------------------------------------------------------
[2023-02-03 14:11:35] bukka@php.net
After some investigation of this I found another related private report that shed a bit more light
on this issue. I was not actually able to use this reproducer even with some modifications as nginx
was constantly returning 499. But managed to get a different one:
touch evil_upload; curl -F 'test=@evil_upload' http://localhost:8080/index.php >/dev/null 2>&1
& CPID=$! && echo $CPID && sleep 10 && kill -9 $CPID; rm evil_upload
The private report actually noted that it was due to bail out which I actually fixed as part of https://github.com/php/php-src/commit/3503b1daa265777588b3219b82219a0056675ca0
so the issue is fixed now.
I should say that this was definitely a security issue in my eyes as it is not true that you can
upload files until out of disk space because we have got a limit max_upload_files. Stas probably
didn't realise that the issue is happening even with this limit in place which should never
happen and disk exhaustion is definitely a problem that should be treated as a security issue. So if
you still manage to recreate this or similar issue with file uploads somehow, please report it as a
new security issue.
------------------------------------------------------------------------
[2018-02-01 02:21:53] c dot r dot l dot f at yandex dot ru
Yep, I just checked it, it's not reproducible when file_uploads = Off.
------------------------------------------------------------------------
[2018-02-01 02:13:29] stas@php.net
So do I understand correctly the problem does not exist when file uploads are disabled?
------------------------------------------------------------------------
[2018-02-01 02:06:42] c dot r dot l dot f at yandex dot ru
In default installations files uploads is always on, so any host that satisfies the dependencies
(PHP+NGINX) can be attacked.
Please look video PoC:
https://alt3r.eg0.ru/p0c5/12a636fcab5953233706dadacfff3ba8.avi
------------------------------------------------------------------------
[2018-02-01 01:36:58] stas@php.net
Isn't that always the case when uploads are allowed - you can upload files until out of disk
space, absent other limitations like quotas, etc.?
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=75889
--
Edit this bug report at https://bugs.php.net/bug.php?id=75889&edit=1