Doc #55516 [Bgs]: is_callable can be a security vulnerability

From: Date: Fri, 26 Aug 2011 23:42:33 +0000
Subject: Doc #55516 [Bgs]: is_callable can be a security vulnerability
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-7068@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=55516&edit=1 ID: 55516 Updated by: stas@php.net Reported by: thegreatall at gmail dot com Summary: is_callable can be a security vulnerability Status: Bogus Type: Documentation Problem Package: Documentation problem Operating System: N/A PHP Version: Irrelevant Block user comment: N Private report: N New Comment: Also, you should use "$var instanceof Closure" in this case :) Previous Comments: ------------------------------------------------------------------------ [2011-08-26 22:59:22] johannes@php.net It is documented, that strings are callable types. We can't prevent all the ways a PHP developer can shoot in his foot. ------------------------------------------------------------------------ [2011-08-26 22:25:09] thegreatall at gmail dot com Description: ------------ If you would be writing a framework or any code that the developer can send a parameter though and the receiving code uses is_callable() to test to see if the variable is a lambda/closure type, they may be opening them selves up to a security vulnerability if the attacker is able to set a string to that variable. I recommend adding a note to that function's documentation saying that if you wish to check to see if a variable is a lambda/closure use "is_a($var, 'Closure')". I know this can be avoided by safe coding, but it can be a huge security issue. Test script: --------------- <?php function buildGrid(array $data){ echo '<table>'; foreach($data as $key => $cell){ if(is_callable($cell)){ // This should be is_a($cell, 'Closure') echo $cell($key); }else{ echo '<tr><td>', htmlentities($key), '</td><td>', htmlentities($cell), '</td></tr>'; } } echo '</table>'; } $array = array( 'id' => $_REQUEST['id'], 'name' => $_REQUEST['name'], 'last_name' => $_REQUEST['last_name'], function ($key){ return '<tr><td>A HEADER OR IMAGE OR SOMETHING THAT CANNOT BE EVALUATED OR DISPLAYED UNLESS CALLED AT COMPILE TIME</td></tr>'; } ); buildGrid($array); /* * If the attacker sent a request like: 'index.php?id=11111&name=somename&last_name=phpinfo' * This will show this attacker all the phpinfo() for the server. This could be vary * dangerious if the programmer had a function like showDebugInfo() as the user could possibly * get very valuble info. */ ?> ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=55516&edit=1

« previous php.doc.bugs (#7068) next »