Bug #18285 Updated: php_checkuid modifies passed filenames/paths
| From: | sniper@php.net | Date: | Fri, 12 Jul 2002 01:15:31 +0000 |
| Subject: | Bug #18285 Updated: php_checkuid modifies passed filenames/paths | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-13893@lists.php.net to get a copy of this message | ||
ID: 18285
Updated by: sniper@php.net
-Summary: Memory Corruption with LANG and Safe Mode
Reported By: ilia@prohost.org
-Status: Open
+Status: Verified
Bug Type: Scripting Engine problem
Operating System: Linux 2.4.17
-PHP Version: 4.2.1
+PHP Version: 4.3.0-dev
New Comment:
The php_checkuid() function in ext/safe_mode.c is fubar.
It modifies the passed filename/path. Also, it's not
possible to pass paths with trailing slash when safe-mode is
enabled.
Previous Comments:
------------------------------------------------------------------------
[2002-07-11 17:09:45] ilia@prohost.org
While trying to make a directory on a system with safe_mode enabled and
LANG enviroemnt variable fi_FI@euro I came across the problem that is
best demonstrated by the script below:
<?php
$src = '/dir/another/dir2/src';
if( !is_dir($src) ) {
echo "no dir $src<br>n";
if( !@mkdir($src, 0755) ) {
echo "cannot make dir: $src<Br>n";
}
}
?>
On the 2nd echo $src string is corrupted, the last / is replaced with a
special character, which Mozilla displayes as a square.
If mkdir($src, 0755) is replaced with mkdir($src.'', 0755) the memory
corruption goes away.
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=18285&edit=1