Bug #15547 Updated: tempnam() bypasses security

From: Date: Tue, 02 Jul 2002 06:17:28 +0000
Subject: Bug #15547 Updated: tempnam() bypasses security
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-12765@lists.php.net to get a copy of this message
ID: 15547 Updated by: derick@php.net Reported By: temisu@utu.fi -Status: Open +Status: Closed Bug Type: Filesystem function related Operating System: Linux(RedHat 7.1) PHP Version: 4.0.6 New Comment: This bug has been fixed in CVS. You can grab a snapshot of the CVS version at http://snaps.php.net/. In case this was a documentation problem, the fix will show up soon at http://www.php.net/manual/. In case this was a PHP.net website problem, the change will show up on the PHP.net site and on the mirror sites. Thank you for the report, and for helping us make PHP better. Previous Comments: ------------------------------------------------------------------------ [2002-02-20 15:37:24] rasmus@php.net open_basedir is completely separate from safe_mode so this is actually a bug. ------------------------------------------------------------------------ [2002-02-19 01:10:53] temisu@utu.fi document http://www.php.net/manual/en/features.safe-mode.php says that If instead of safe_mode, you set an open_basedir directory ^^^^^^^ then all file operations will be limited to files under the specified directory For example (Apache httpd.conf example): ------------------------------------------------------------------------ [2002-02-18 10:20:29] sander@php.net AFAIK, open_basedir restrictions only _work_ when having safe_mode ON. ------------------------------------------------------------------------ [2002-02-18 01:44:15] temisu@utu.fi > Are you sure safe-mode is enabled? No it is not. open_basedir seems to be independent directive without connection to the safe-mode (Atleast, the directory restrictions work on other file-operations but not tempnam) The following is example what triggered this in my code. php.ini has open_basedir=/www/htdocs and safe_mode= off The working code... $tfile=tempnam("/www/htdocs/tmp","foobar"); // success if /www/htdocs/tmp/ exists and is writable // directory $fp=fopen($tfile,"w"); // opens the file. The initial version, which does not care about the open_basedir... $tfile=tempnam("/tmp","foobar"); // creates the temp-file. $fp=fopen($tfile,"w"); // tries to open the file but does not succeed because of // the open_basedir setting! // // Because (any other) file operations cannot be used on /tmp // this code clutters the /tmp directory with zerobyte // temp-files. ------------------------------------------------------------------------ [2002-02-15 13:08:10] sander@php.net Are you sure safe-mode is enabled? ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at http://bugs.php.net/15547 -- Edit this bug report at http://bugs.php.net/?id=15547&edit=1

« previous php.bugs (#12765) next »