Bug #76359 [Ana->Csd]: open_basedir bypass through adding ".."
| From: | git@php.net | Date: | Tue, 25 May 2021 11:48:29 +0000 |
| Subject: | Bug #76359 [Ana->Csd]: open_basedir bypass through adding ".." | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-234015@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=76359&edit=1
ID: 76359
Updated by: git@php.net
Reported by: buglloc at yandex dot ru
Summary: open_basedir bypass through adding ".."
-Status: Analyzed
+Status: Closed
Type: Bug
Package: Safe Mode/open_basedir
Operating System: GNU/Linux
PHP Version: 7.2.5
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of cmb69
Revision: https://github.com/php/php-src/commit/ee9e07541f9f07762e3ee781102eea3a4190787c
Log: Fix #76359: open_basedir bypass through adding ".."
Previous Comments:
------------------------------------------------------------------------
[2021-05-21 10:51:26] cmb@php.net
The following pull request has been associated:
Patch Name: Fix #76359: open_basedir bypass through adding ".."
On GitHub: https://github.com/php/php-src/pull/7024
Patch: https://github.com/php/php-src/pull/7024.patch
------------------------------------------------------------------------
[2021-05-21 10:50:57] cmb@php.net
> the purpose of open_basedir is that customer A can't
> write/access to webspace from customer B
Nope.
BTW, I liked it more when you used the self-describing mail
address *spam* AT rhsoft DOT net.
------------------------------------------------------------------------
[2021-05-21 10:17:57] rtrtrtrtrt at dfdfdfdf dot dfd
> open_basedir isn't meant to protect the system from a local user.
> open_basedir is meant to protect an application from accessing
> directories it was not written to access
this is wrong!
the purpose of open_basedir is that customer A can't write/access to webspace from customer B
and please don't come up with containers
------------------------------------------------------------------------
[2021-05-21 10:10:26] cmb@php.net
Indeed, this is not a security issue according to our
classification[1].
[1] <https://wiki.php.net/security>
------------------------------------------------------------------------
[2018-05-20 21:08:18] rasmus@php.net
You left out the 3rd and most important pre-condition there. That the attacker can write arbitrary
PHP code and execute it. With that condition it is game over.
open_basedir isn't meant to protect the system from a local user. open_basedir is meant to
protect an application from accessing directories it was not written to access. In your case you are
writing an application explicitly to circumvent open_basedir which is well outside its scope.
Having said that, I can't see any reason to ever allow adding ".." to open_basedir at
runtime which is an easy fix.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=76359
--
Edit this bug report at https://bugs.php.net/bug.php?id=76359&edit=1