Req #25572 [Opn->Wfx]: safe_mode ignores uid of files written
| From: | levim@php.net | Date: | Thu, 17 Apr 2014 14:21:15 +0000 |
| Subject: | Req #25572 [Opn->Wfx]: safe_mode ignores uid of files written | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-185324@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=25572&edit=1
ID: 25572
Updated by: levim@php.net
Reported by: Andreas dot Ley at rz dot uni-karlsruhe dot de
Summary: safe_mode ignores uid of files written
-Status: Open
+Status: Wont fix
Type: Feature/Change Request
-Package: Feature/Change Request
+Package: *General Issues
PHP Version: 4.3.3
Block user comment: N
Private report: N
New Comment:
This won't be fixed. Safe mode was deprecated in PHP 5.3 and removed in PHP 5.4/
Previous Comments:
------------------------------------------------------------------------
[2003-09-17 09:28:02] Andreas dot Ley at rz dot uni-karlsruhe dot de
Description:
------------
When using PHP as an apache module and safe_mode is on, PHP checks wether the owner of the script
and the owner of the directory where a file should be written match. However, this owner and the uid
of the apache process which runs the PHP script may be different (multi-user system with one apache
but may user homepages). Thus a user may be able to create files which are owned by the apache user
- this is a problem when quotas are enabled to restrict user diskspace usage.
A solution to this issue would be to also check the uid of the apache process against the owner of
the directory. A possible implementation is this patch:
http://andy.rz.uni-karlsruhe.de/~andy/source/Patches/php-4.3.3/safe_mode_write-patch
This changes PHPs behaviour in a way which may or may not be desirable at different sites, so this
should be configurable either in configure or in php.ini.
This differs from bug #18407, since I don't want to read apache owned files but need to prevent
them created (which circumvents quotas). As gtg782a suggested in the notes at http://www.php.net/manual/en/features.safe-mode.php,
another solution would be to (safe and secure) change the owner of the files written; this seems
much more complicated to me.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=25572&edit=1