Bug #41655 [Com]: open_basedir bypass via glob()
| From: | ocean_J01 at 163 dot com | Date: | Sat, 31 Mar 2018 11:31:44 +0000 |
| Subject: | Bug #41655 [Com]: open_basedir bypass via glob() | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-214548@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=41655&edit=1
ID: 41655
Comment by: ocean_J01 at 163 dot com
Reported by: dr at peytz dot dk
Summary: open_basedir bypass via glob()
Status: Closed
Type: Bug
Package: Safe Mode/open_basedir
Operating System: Linux
PHP Version: 5.2.3
Assigned To: iliaa
Block user comment: N
Private report: N
New Comment:
Me too!
Previous Comments:
------------------------------------------------------------------------
[2015-10-17 14:14:04] bugs at tmarques dot com
Related To: Bug #69693
------------------------------------------------------------------------
[2007-09-19 22:40:10] iliaa@php.net
This bug has been fixed in CVS.
Snapshots of the sources are packaged every three hours; this change
will be in the next snapshot. You can grab the snapshot at
http://snaps.php.net/.
Thank you for the report, and for helping us make PHP better.
------------------------------------------------------------------------
[2007-09-18 20:36:58] pajoye@php.net
Please, you can't break BC at this point. My example works before and must work now.
/home/pierre/cvs/php52/ext/*/tests/../../../../../*
has nothing to do with my example except that you add relative paths later. It is simply another
case that should fail because of open_basedir.
My example introduces a huge BC break in symfony, to list only one widely used "app". Back
to open, if you don't want to fix it yourself, please let me know, I will have to do it myself.
------------------------------------------------------------------------
[2007-09-18 19:08:04] iliaa@php.net
This is unavoidable since you don't want things like:
/home/pierre/cvs/php52/ext/*/tests/../../../../../*
to be let through.
------------------------------------------------------------------------
[2007-09-17 07:51:11] pajoye@php.net
The fix for this bug introduced a regression.
Using:
$a =glob("/home/pierre/cvs/php52/ext/*/tests/*");'
Where:
open_basedir = /home/pierre/cvs/php52
glob fails to access this path:
Warning: glob(): Unable to access /home/pierre/cvs/php52/ext/*/tests in Command line code on line 1
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=41655
--
Edit this bug report at https://bugs.php.net/bug.php?id=41655&edit=1