Req #25572 [Opn->Wfx]: safe_mode ignores uid of files written

From: Date: Thu, 17 Apr 2014 14:21:15 +0000
Subject: Req #25572 [Opn->Wfx]: safe_mode ignores uid of files written
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-185324@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=25572&edit=1 ID: 25572 Updated by: levim@php.net Reported by: Andreas dot Ley at rz dot uni-karlsruhe dot de Summary: safe_mode ignores uid of files written -Status: Open +Status: Wont fix Type: Feature/Change Request -Package: Feature/Change Request +Package: *General Issues PHP Version: 4.3.3 Block user comment: N Private report: N New Comment: This won't be fixed. Safe mode was deprecated in PHP 5.3 and removed in PHP 5.4/ Previous Comments: ------------------------------------------------------------------------ [2003-09-17 09:28:02] Andreas dot Ley at rz dot uni-karlsruhe dot de Description: ------------ When using PHP as an apache module and safe_mode is on, PHP checks wether the owner of the script and the owner of the directory where a file should be written match. However, this owner and the uid of the apache process which runs the PHP script may be different (multi-user system with one apache but may user homepages). Thus a user may be able to create files which are owned by the apache user - this is a problem when quotas are enabled to restrict user diskspace usage. A solution to this issue would be to also check the uid of the apache process against the owner of the directory. A possible implementation is this patch: http://andy.rz.uni-karlsruhe.de/~andy/source/Patches/php-4.3.3/safe_mode_write-patch This changes PHPs behaviour in a way which may or may not be desirable at different sites, so this should be configurable either in configure or in php.ini. This differs from bug #18407, since I don't want to read apache owned files but need to prevent them created (which circumvents quotas). As gtg782a suggested in the notes at http://www.php.net/manual/en/features.safe-mode.php, another solution would be to (safe and secure) change the owner of the files written; this seems much more complicated to me. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=25572&edit=1

« previous php.bugs (#185324) next »