[php-src] Issue #12344: Set register_argc_argv to Off by default
| From: | thomas-chauchefoin-sonarsource | Date: | Mon, 02 Oct 2023 12:50:07 +0000 |
| Subject: | [php-src] Issue #12344: Set register_argc_argv to Off by default | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-245476@lists.php.net to get a copy of this message | ||
Issue: https://github.com/php/php-src/issues/12344
Author: thomas-chauchefoin-sonarsource
### Description
_(I'm not reporting this as a [security issue](https://github.com/php/php-src/security) as
it's about a setting "[...] not recommended for production - ex. error reporting to
output" or "[...] known to be insecure".)_
Many PHP CLI tools are shipped in the form of Phar files (e.g. Composer), and while never really
recommended, some users tend to put these archives under the web root (tutorials from shared hosting
providers, when you need per-project Composer releases, etc.). [On distributions like Debian and
Ubuntu, Apache is treating these files as PHP
scripts](https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=639268).
Since these scripts use
$_SERVER['argc'] to find out how they are invoked and
parse their arguments, direct access to these files is not a problem when
register_argc_argv is set to Off. Looking into this topic, I noticed that
PHP is still shipped with register_argc_argv set to On by default:
https://github.com/php/php-src/blob/21d9fd3bc1ccf376438e4b5c38bb1945ae3bfe8c/main/main.c#L709
The recommended default configuration for the production environment and shipped with most
distributions set it to Off–note that it only mentions performance reasons and not
security:
https://github.com/php/php-src/blob/21d9fd3bc1ccf376438e4b5c38bb1945ae3bfe8c/php.ini-production#L677-L690
There are still environments in which this setting can be set to On, either
involuntarily by keeping the development configuration or voluntarily by manually setting it. For
instance, [the official Docker image](https://hub.docker.com/_/php) for PHP has it set to
On.
We can then assume that there is a non-zero chance of deployments processing Phar files as PHP
scripts _and_ with this setting left to its default value, introducing potential vulnerabilities.
I've already reached out to Composer and they now refuse to run in non-CLI SAPIs if
register_argc_argv is On (CVE-2023-43655).
Outside of the risk caused by Phar files, register_argc_argv is also a known
"trick" to exploit limited Local File Inclusion vulnerabilities in a generic way in Docker
php images, using /usr/local/lib/php/pearcmd.php (i.e.
[2linephp](https://github.com/w181496/My-CTF-Challenges/tree/master/Balsn-CTF-2021#2linephp) by
@w181496 during Balsn CTF 2021).
I think it would be great to set register_argc_argv to Off by default,
keeping it to On only for these SAPIs: embed, phpdbg and
cli. I'm not sure about litespeed but from what I'm reading in
the code, it seems important too. The documentation in php.ini could also mention the
potential security risks caused by this setting.
I'll be happy to work on the PR if this sounds like something that could happen to be merged,
let me know!