mirror of
https://github.com/php/php-src.git
synced 2026-04-04 22:52:40 +02:00
Fix bug #67498 - phpinfo() Type Confusion Information Leak Vulnerability
This commit is contained in:
@@ -972,16 +972,16 @@ PHPAPI void php_print_info(int flag TSRMLS_DC)
|
||||
|
||||
php_info_print_table_start();
|
||||
php_info_print_table_header(2, "Variable", "Value");
|
||||
if (zend_hash_find(&EG(symbol_table), "PHP_SELF", sizeof("PHP_SELF"), (void **) &data) != FAILURE) {
|
||||
if (zend_hash_find(&EG(symbol_table), "PHP_SELF", sizeof("PHP_SELF"), (void **) &data) != FAILURE && Z_TYPE_PP(data) == IS_STRING) {
|
||||
php_info_print_table_row(2, "PHP_SELF", Z_STRVAL_PP(data));
|
||||
}
|
||||
if (zend_hash_find(&EG(symbol_table), "PHP_AUTH_TYPE", sizeof("PHP_AUTH_TYPE"), (void **) &data) != FAILURE) {
|
||||
if (zend_hash_find(&EG(symbol_table), "PHP_AUTH_TYPE", sizeof("PHP_AUTH_TYPE"), (void **) &data) != FAILURE && Z_TYPE_PP(data) == IS_STRING) {
|
||||
php_info_print_table_row(2, "PHP_AUTH_TYPE", Z_STRVAL_PP(data));
|
||||
}
|
||||
if (zend_hash_find(&EG(symbol_table), "PHP_AUTH_USER", sizeof("PHP_AUTH_USER"), (void **) &data) != FAILURE) {
|
||||
if (zend_hash_find(&EG(symbol_table), "PHP_AUTH_USER", sizeof("PHP_AUTH_USER"), (void **) &data) != FAILURE && Z_TYPE_PP(data) == IS_STRING) {
|
||||
php_info_print_table_row(2, "PHP_AUTH_USER", Z_STRVAL_PP(data));
|
||||
}
|
||||
if (zend_hash_find(&EG(symbol_table), "PHP_AUTH_PW", sizeof("PHP_AUTH_PW"), (void **) &data) != FAILURE) {
|
||||
if (zend_hash_find(&EG(symbol_table), "PHP_AUTH_PW", sizeof("PHP_AUTH_PW"), (void **) &data) != FAILURE && Z_TYPE_PP(data) == IS_STRING) {
|
||||
php_info_print_table_row(2, "PHP_AUTH_PW", Z_STRVAL_PP(data));
|
||||
}
|
||||
php_print_gpcse_array("_REQUEST", sizeof("_REQUEST")-1 TSRMLS_CC);
|
||||
|
||||
15
ext/standard/tests/general_functions/bug67498.phpt
Normal file
15
ext/standard/tests/general_functions/bug67498.phpt
Normal file
@@ -0,0 +1,15 @@
|
||||
--TEST--
|
||||
phpinfo() Type Confusion Information Leak Vulnerability
|
||||
--FILE--
|
||||
<?php
|
||||
$PHP_SELF = 1;
|
||||
phpinfo(INFO_VARIABLES);
|
||||
|
||||
?>
|
||||
==DONE==
|
||||
--EXPECTF--
|
||||
phpinfo()
|
||||
|
||||
PHP Variables
|
||||
%A
|
||||
==DONE==
|
||||
Reference in New Issue
Block a user