Skip to content

Commit ec002bd

Browse files
committed
Fix bug #67498 - phpinfo() Type Confusion Information Leak Vulnerability
1 parent 52de149 commit ec002bd

File tree

2 files changed

+19
-4
lines changed

2 files changed

+19
-4
lines changed

ext/standard/info.c

+4-4
Original file line numberDiff line numberDiff line change
@@ -972,16 +972,16 @@ PHPAPI void php_print_info(int flag TSRMLS_DC)
972972

973973
php_info_print_table_start();
974974
php_info_print_table_header(2, "Variable", "Value");
975-
if (zend_hash_find(&EG(symbol_table), "PHP_SELF", sizeof("PHP_SELF"), (void **) &data) != FAILURE) {
975+
if (zend_hash_find(&EG(symbol_table), "PHP_SELF", sizeof("PHP_SELF"), (void **) &data) != FAILURE && Z_TYPE_PP(data) == IS_STRING) {
976976
php_info_print_table_row(2, "PHP_SELF", Z_STRVAL_PP(data));
977977
}
978-
if (zend_hash_find(&EG(symbol_table), "PHP_AUTH_TYPE", sizeof("PHP_AUTH_TYPE"), (void **) &data) != FAILURE) {
978+
if (zend_hash_find(&EG(symbol_table), "PHP_AUTH_TYPE", sizeof("PHP_AUTH_TYPE"), (void **) &data) != FAILURE && Z_TYPE_PP(data) == IS_STRING) {
979979
php_info_print_table_row(2, "PHP_AUTH_TYPE", Z_STRVAL_PP(data));
980980
}
981-
if (zend_hash_find(&EG(symbol_table), "PHP_AUTH_USER", sizeof("PHP_AUTH_USER"), (void **) &data) != FAILURE) {
981+
if (zend_hash_find(&EG(symbol_table), "PHP_AUTH_USER", sizeof("PHP_AUTH_USER"), (void **) &data) != FAILURE && Z_TYPE_PP(data) == IS_STRING) {
982982
php_info_print_table_row(2, "PHP_AUTH_USER", Z_STRVAL_PP(data));
983983
}
984-
if (zend_hash_find(&EG(symbol_table), "PHP_AUTH_PW", sizeof("PHP_AUTH_PW"), (void **) &data) != FAILURE) {
984+
if (zend_hash_find(&EG(symbol_table), "PHP_AUTH_PW", sizeof("PHP_AUTH_PW"), (void **) &data) != FAILURE && Z_TYPE_PP(data) == IS_STRING) {
985985
php_info_print_table_row(2, "PHP_AUTH_PW", Z_STRVAL_PP(data));
986986
}
987987
php_print_gpcse_array("_REQUEST", sizeof("_REQUEST")-1 TSRMLS_CC);
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
--TEST--
2+
phpinfo() Type Confusion Information Leak Vulnerability
3+
--FILE--
4+
<?php
5+
$PHP_SELF = 1;
6+
phpinfo(INFO_VARIABLES);
7+
8+
?>
9+
==DONE==
10+
--EXPECTF--
11+
phpinfo()
12+
13+
PHP Variables
14+
%A
15+
==DONE==

0 commit comments

Comments
 (0)