Bug #76359 [Ana->Csd]: open_basedir bypass through adding ".."

From: Date: Tue, 25 May 2021 11:48:29 +0000
Subject: Bug #76359 [Ana->Csd]: open_basedir bypass through adding ".."
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-234015@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76359&edit=1 ID: 76359 Updated by: git@php.net Reported by: buglloc at yandex dot ru Summary: open_basedir bypass through adding ".." -Status: Analyzed +Status: Closed Type: Bug Package: Safe Mode/open_basedir Operating System: GNU/Linux PHP Version: 7.2.5 Assigned To: cmb Block user comment: N Private report: N New Comment: Automatic comment on behalf of cmb69 Revision: https://github.com/php/php-src/commit/ee9e07541f9f07762e3ee781102eea3a4190787c Log: Fix #76359: open_basedir bypass through adding &quot;..&quot; Previous Comments: ------------------------------------------------------------------------ [2021-05-21 10:51:26] cmb@php.net The following pull request has been associated: Patch Name: Fix #76359: open_basedir bypass through adding ".." On GitHub: https://github.com/php/php-src/pull/7024 Patch: https://github.com/php/php-src/pull/7024.patch ------------------------------------------------------------------------ [2021-05-21 10:50:57] cmb@php.net > the purpose of open_basedir is that customer A can't > write/access to webspace from customer B Nope. BTW, I liked it more when you used the self-describing mail address *spam* AT rhsoft DOT net. ------------------------------------------------------------------------ [2021-05-21 10:17:57] rtrtrtrtrt at dfdfdfdf dot dfd > open_basedir isn't meant to protect the system from a local user. > open_basedir is meant to protect an application from accessing > directories it was not written to access this is wrong! the purpose of open_basedir is that customer A can't write/access to webspace from customer B and please don't come up with containers ------------------------------------------------------------------------ [2021-05-21 10:10:26] cmb@php.net Indeed, this is not a security issue according to our classification[1]. [1] <https://wiki.php.net/security> ------------------------------------------------------------------------ [2018-05-20 21:08:18] rasmus@php.net You left out the 3rd and most important pre-condition there. That the attacker can write arbitrary PHP code and execute it. With that condition it is game over. open_basedir isn't meant to protect the system from a local user. open_basedir is meant to protect an application from accessing directories it was not written to access. In your case you are writing an application explicitly to circumvent open_basedir which is well outside its scope. Having said that, I can't see any reason to ever allow adding ".." to open_basedir at runtime which is an easy fix. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=76359 -- Edit this bug report at https://bugs.php.net/bug.php?id=76359&edit=1

« previous php.bugs (#234015) next »