Re: Security implications of parsing env variables in .ini
| From: | Dusk | Date: | Fri, 14 Jul 2023 16:33:05 +0000 |
| Subject: | Re: Security implications of parsing env variables in .ini | ||
| References: | 1 2 3 4 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-120820@lists.php.net to get a copy of this message | ||
On Jul 14, 2023, at 09:03, David Gebler <davidgebler@gmail.com> wrote:
> On Fri, Jul 14, 2023 at 3:08 AM Dusk <dusk@woofle.net> wrote:
>> 2) These expansions should probably be disabled by INI_SCANNER_RAW; that
>> flag already disables certain other types of value interpolation. (Oddly,
>> it doesn't disable expansion of constants either; that might be worth
>> revisiting as well.)
>
> Environment variable parsing is already disabled by INI_SCANNER_RAW mode,
> isn't it?
Oops! You're correct (and it does also disable constant expansion). I was passing the flag to
$process_sections by mistake.