Bug #42560 [Opn->Csd]: Empty directory argument to tempnam yields open_basedir problems

From: Date: Tue, 19 Jan 2021 10:45:02 +0000
Subject: Bug #42560 [Opn->Csd]: Empty directory argument to tempnam yields open_basedir problems
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-231631@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=42560&edit=1 ID: 42560 Updated by: nikic@php.net Reported by: Bjorn dot Wiberg at its dot uu dot se Summary: Empty directory argument to tempnam yields open_basedir problems -Status: Open +Status: Closed Type: Bug Package: Safe Mode/open_basedir Operating System: IBM AIX 5.3 5300-08-01-0819 PHP Version: 5.2.9 Block user comment: N Private report: N New Comment: Automatic comment on behalf of shinji.igarashi@gmail.com Revision: http://git.php.net/?p=php-src.git;a=commit;h=5d31ee302db073d5e99cf307315d2d631eaa34a5 Log: Fixed bug #42560 Previous Comments: ------------------------------------------------------------------------ [2020-12-20 21:58:35] sji at sj-i dot dev https://github.com/php/php-src/pull/6526 This PR fixes the problem. ------------------------------------------------------------------------ [2010-02-16 12:31:33] jeffersongranatto at mannesoft dot com dot br ...or active "open_basedir_check" in php_open_temporary_fd ------------------------------------------------------------------------ [2010-02-16 03:13:27] jeffersongranatto at mannesoft dot com dot br I think... this will not cause side effects. in the file: ext/standard/file.c in the function: PHP_FUNCTION(tempnam) remove: if (php_check_open_basedir(dir TSRMLS_CC)) { RETURN_FALSE; } in the file: main/php_open_temporary_file.c in the function: PHPAPI int php_open_temporary_fd_ex include before the comment: /* Try the directory given as parameter. */ this: if (php_check_open_basedir(dir TSRMLS_CC)) { return -1; } And remove this: !open_basedir_check It seems it does not work, and now it will be bad. ------------------------------------------------------------------------ [2009-08-26 05:45:13] Bjorn dot Wiberg at its dot uu dot se (Don't know about 5.2.10; bug #48276 hinders us from installing that one on our systems, so personally I cannot verify any changes before 5.2.11 but I'm sure you or some of the other people who have reported this can. The sample code is included with the original submission.) ------------------------------------------------------------------------ [2009-08-26 05:36:04] Bjorn dot Wiberg at its dot uu dot se I also verified this, the problem is still present in PHP 5.2.9: Warning: tempnam(): open_basedir restriction in effect. File() is not within the allowed path(s): (.:/apache/php/lib/php:/opt/freeware/bin:/tmp:/usr/local/bin:/usr/local/etc/Counter/data:/apache/htdocs/bwiberg) in /apache/htdocs/bwiberg/test/tempnam.php on line 2 (and no /tmp/test file present) ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=42560 -- Edit this bug report at https://bugs.php.net/bug.php?id=42560&edit=1

« previous php.bugs (#231631) next »