PHP 4.0 Bug #6351: '%'-characters in syslog()-function
| From: | jjaakkol at cs dot helsinki dot fi | Date: | Fri, 25 Aug 2000 12:22:27 +0000 |
| Subject: | PHP 4.0 Bug #6351: '%'-characters in syslog()-function | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-30632@lists.php.net to get a copy of this message | ||
From: jjaakkol@cs.helsinki.fi
Operating system: Any OS with syslog()
PHP version: 4.0.1pl2
PHP Bug Type: Misbehaving function
Bug description: '%'-characters in syslog()-function
syslog() function has a client given format string vulneralibity (this is actually
known, since there is a comment on this in the sources).
# cat test.php
<?php
syslog(5,"%s");
?>
# php4 test.php
Content-type: text/html
# tail -1 /var/log/messages
Aug 25 15:05:12 demonstration php4: U?åfì^HVS<u^Lf}^H^Bu^W?EüP?EøPj^BèÄ^^A
However, I guess that this could be exploited to gain access to PHP-server in scripts who syslog()
some client given data. So this is a security problem too.
The simple fix is to change the line
php_syslog((*priority)->value.lval, (*message)->value.str.val);
in ext/standard/syslog.c to
php_syslog((*priority)->value.lval,"%s", (*message)->value.str.val);