PHP 4.0 Bug #6351: '%'-characters in syslog()-function

From: Date: Fri, 25 Aug 2000 12:22:27 +0000
Subject: PHP 4.0 Bug #6351: '%'-characters in syslog()-function
Groups: php.dev 
Request: Send a blank email to php-dev+get-30632@lists.php.net to get a copy of this message
From: jjaakkol@cs.helsinki.fi Operating system: Any OS with syslog() PHP version: 4.0.1pl2 PHP Bug Type: Misbehaving function Bug description: '%'-characters in syslog()-function syslog() function has a client given format string vulneralibity (this is actually known, since there is a comment on this in the sources). # cat test.php <?php syslog(5,"%s"); ?> # php4 test.php Content-type: text/html # tail -1 /var/log/messages Aug 25 15:05:12 demonstration php4: U?åfì^HVS<u^Lf}^H^Bu^W?EüP?EøPj^BèÄ^^A However, I guess that this could be exploited to gain access to PHP-server in scripts who syslog() some client given data. So this is a security problem too. The simple fix is to change the line php_syslog((*priority)->value.lval, (*message)->value.str.val); in ext/standard/syslog.c to php_syslog((*priority)->value.lval,"%s", (*message)->value.str.val);

« previous php.dev (#30632) next »