Bug #15547 Updated: tempnam() bypasses security
| From: | shane at aaatechnologiesaus dot net | Date: | Sun, 14 Jul 2002 10:04:20 +0000 |
| Subject: | Bug #15547 Updated: tempnam() bypasses security | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-14130@lists.php.net to get a copy of this message | ||
ID: 15547
Updated by: shane@aaatechnologiesaus.net
Reported By: temisu@utu.fi
Status: Closed
Bug Type: Filesystem function related
Operating System: Linux(RedHat 7.1)
PHP Version: 4.0.6
New Comment:
open_basedir =/var/vhosts/sites:/tmp/
Previous Comments:
------------------------------------------------------------------------
[2002-07-02 02:17:28] derick@php.net
This bug has been fixed in CVS. You can grab a snapshot of the
CVS version at http://snaps.php.net/. In case this was a
documentation
problem, the fix will show up soon at http://www.php.net/manual/.
In case this was a PHP.net website problem, the change will show
up on the PHP.net site and on the mirror sites.
Thank you for the report, and for helping us make PHP better.
------------------------------------------------------------------------
[2002-02-20 15:37:24] rasmus@php.net
open_basedir is completely separate from safe_mode so this is actually
a bug.
------------------------------------------------------------------------
[2002-02-19 01:10:53] temisu@utu.fi
document
http://www.php.net/manual/en/features.safe-mode.php
says that
If instead of safe_mode, you set an open_basedir directory
^^^^^^^
then all file operations will be limited to files under the specified
directory For example (Apache httpd.conf example):
------------------------------------------------------------------------
[2002-02-18 10:20:29] sander@php.net
AFAIK, open_basedir restrictions only _work_ when having safe_mode ON.
------------------------------------------------------------------------
[2002-02-18 01:44:15] temisu@utu.fi
> Are you sure safe-mode is enabled?
No it is not. open_basedir seems to be independent directive
without connection to the safe-mode (Atleast, the directory
restrictions work on other file-operations but not tempnam)
The following is example what triggered this in my code.
php.ini has open_basedir=/www/htdocs and safe_mode= off
The working code...
$tfile=tempnam("/www/htdocs/tmp","foobar");
// success if /www/htdocs/tmp/ exists and is writable
// directory
$fp=fopen($tfile,"w");
// opens the file.
The initial version, which does not care about the
open_basedir...
$tfile=tempnam("/tmp","foobar");
// creates the temp-file.
$fp=fopen($tfile,"w");
// tries to open the file but does not succeed because of
// the open_basedir setting!
//
// Because (any other) file operations cannot be used on /tmp
// this code clutters the /tmp directory with zerobyte
// temp-files.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
http://bugs.php.net/15547
--
Edit this bug report at http://bugs.php.net/?id=15547&edit=1