4 ms·
From Twitter: Stefan Esser @i0n1c The security emergency release to fix the PHP CGI RCE (that was tested for days...) does not fix anything at all.
by endijs 14y ago
From Twitter:
Stefan Esser @i0n1c
The security emergency release to fix the PHP CGI RCE (that was tested for days...) does not fix anything at all.
- 0x0 14y agoHere is the fix that was applied: https://github.com/php/php-src/commit/55869a95ab75c0eb99c57201bfeccaef57e0d36d https://github.com/php/php-src/commit/55869a95ab75c0eb99c572... If the first char in the query string is "-" and the query string also contains "=", it skips cmdline argument option parsing. Maybe it is possible to construct a string not starting with "-", not containing "=", but containing a "+" followed by "-options" further out?
- sirclueless 14y agoNo, the problem is that they check the decoded query string for `=` signs, but Apache checks the raw query string. If you pass an encoded `=` anywhere in the query string then you can bypass the fix.