Bug #18285 Updated: php_checkuid modifies passed filenames/paths

From: Date: Sat, 13 Jul 2002 00:52:28 +0000
Subject: Bug #18285 Updated: php_checkuid modifies passed filenames/paths
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-14038@lists.php.net to get a copy of this message
ID: 18285 Updated by: sniper@php.net Reported By: ilia@prohost.org -Status: Verified +Status: Closed Bug Type: Scripting Engine problem Operating System: Linux 2.4.17 PHP Version: 4.3.0-dev New Comment: This bug has been fixed in CVS. You can grab a snapshot of the CVS version at http://snaps.php.net/. In case this was a documentation problem, the fix will show up soon at http://www.php.net/manual/. In case this was a PHP.net website problem, the change will show up on the PHP.net site and on the mirror sites. Thank you for the report, and for helping us make PHP better. Previous Comments: ------------------------------------------------------------------------ [2002-07-11 21:15:30] sniper@php.net The php_checkuid() function in ext/safe_mode.c is fubar. It modifies the passed filename/path. Also, it's not possible to pass paths with trailing slash when safe-mode is enabled. ------------------------------------------------------------------------ [2002-07-11 17:09:45] ilia@prohost.org While trying to make a directory on a system with safe_mode enabled and LANG enviroemnt variable fi_FI@euro I came across the problem that is best demonstrated by the script below: <?php $src = '/dir/another/dir2/src'; if( !is_dir($src) ) { echo "no dir $src<br>n"; if( !@mkdir($src, 0755) ) { echo "cannot make dir: $src<Br>n"; } } ?> On the 2nd echo $src string is corrupted, the last / is replaced with a special character, which Mozilla displayes as a square. If mkdir($src, 0755) is replaced with mkdir($src.'', 0755) the memory corruption goes away. ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=18285&edit=1

« previous php.bugs (#14038) next »