Re: Security implications of parsing env variables in .ini

From: Date: Fri, 14 Jul 2023 16:33:05 +0000
Subject: Re: Security implications of parsing env variables in .ini
References: 1 2 3 4  Groups: php.internals 
Request: Send a blank email to internals+get-120820@lists.php.net to get a copy of this message
On Jul 14, 2023, at 09:03, David Gebler <davidgebler@gmail.com> wrote: > On Fri, Jul 14, 2023 at 3:08 AM Dusk <dusk@woofle.net> wrote: >> 2) These expansions should probably be disabled by INI_SCANNER_RAW; that >> flag already disables certain other types of value interpolation. (Oddly, >> it doesn't disable expansion of constants either; that might be worth >> revisiting as well.) > > Environment variable parsing is already disabled by INI_SCANNER_RAW mode, > isn't it? Oops! You're correct (and it does also disable constant expansion). I was passing the flag to $process_sections by mistake.

« previous php.internals (#120820) next »