Re: Security implications of parsing env variables in .ini

From: Date: Fri, 14 Jul 2023 16:03:49 +0000
Subject: Re: Security implications of parsing env variables in .ini
References: 1 2 3  Groups: php.internals 
Request: Send a blank email to internals+get-120819@lists.php.net to get a copy of this message
On Fri, Jul 14, 2023 at 3:08 AM Dusk <dusk@woofle.net> wrote: > 2) These expansions should probably be disabled by INI_SCANNER_RAW; that > flag already disables certain other types of value interpolation. (Oddly, > it doesn't disable expansion of constants either; that might be worth > revisiting as well.) Environment variable parsing is already disabled by INI_SCANNER_RAW mode, isn't it? Personally I don't think the default/normal mode should behave differently. If you're passing untrusted input to parse_ini_string, you should be sanitizing, white listing or using raw mode anyway really.

« previous php.internals (#120819) next »