Bug #14370 Updated: PHP_AUTH_PW being improperly set
| From: | sniper@php.net | Date: | Thu, 13 Jun 2002 22:14:08 +0000 |
| Subject: | Bug #14370 Updated: PHP_AUTH_PW being improperly set | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-10407@lists.php.net to get a copy of this message | ||
ID: 14370
Updated by: sniper@php.net
Reported By: henrich@msu.edu
-Status: Open
+Status: Closed
Bug Type: Apache related
Operating System: FreeBSD
PHP Version: 4.0.6
New Comment:
This bug has been fixed in CVS. You can grab a snapshot of the
CVS version at http://snaps.php.net/. In case this was a
documentation
problem, the fix will show up soon at http://www.php.net/manual/.
In case this was a PHP.net website problem, the change will show
up on the PHP.net site and on the mirror sites.
Thank you for the report, and for helping us make PHP better.
Previous Comments:
------------------------------------------------------------------------
[2002-03-11 07:37:49] php4@Ncc-1701.b.shuttle.DE
The following patch solves this bug by not exporting the PHP_AUTH_*
variables if safe_mode is set.
===8<====================================================
--- php-4.1.2/main/main.c.orig-securevars Mon Dec 17 22:19:51
2001
+++ php-4.1.2/main/main.c Mon Mar 11 07:34:40 2002
@@ -1031,10 +1031,10 @@
}
/* PHP Authentication support */
- if (SG(request_info).auth_user) {
+ if (!PG(safe_mode) && SG(request_info).auth_user) {
php_register_variable("PHP_AUTH_USER",
SG(request_info).auth_user, array_ptr TSRMLS_CC);
}
- if (SG(request_info).auth_password) {
+ if (!PG(safe_mode) && SG(request_info).auth_password) {
php_register_variable("PHP_AUTH_PW",
SG(request_info).auth_password, array_ptr TSRMLS_CC);
}
}
------------------------------------------------------------------------
[2002-03-11 07:36:53] php4@Ncc-1701.b.shuttle.DE
The following patch solves this bug by not exporting the PHP_AUTH_*
variables when safe_mode is set.
===8<====================================================
--- php-4.1.2/main/main.c.orig-securevars Mon Dec 17 22:19:51
2001
+++ php-4.1.2/main/main.c Mon Mar 11 07:34:40 2002
@@ -1031,10 +1031,10 @@
}
/* PHP Authentication support */
- if (SG(request_info).auth_user) {
+ if (!PG(safe_mode) && SG(request_info).auth_user) {
php_register_variable("PHP_AUTH_USER",
SG(request_info).auth_user, array_ptr TSRMLS_CC);
}
- if (SG(request_info).auth_password) {
+ if (!PG(safe_mode) && SG(request_info).auth_password) {
php_register_variable("PHP_AUTH_PW",
SG(request_info).auth_password, array_ptr TSRMLS_CC);
}
}
------------------------------------------------------------------------
[2001-12-06 19:34:29] henrich@msu.edu
PHP_AUTH_PW is being improperly set when external authentication is
active
on Apache.
I have a directory structure that is protected via Apache
authentication, according
to the PHP documentation the PHP_AUTH_PW should not be available when
external authentication is in use. This is necessary for security
concerns when you
cannot trust the php applications. In any case, w/ php the AUTH_PW is
being
set at all times. Please fix, thanks!
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=14370&edit=1