Sec Bug->Bug #63904 [Opn]: open_basedir is not respected for .user.ini files

From: Date: Mon, 12 Jul 2021 15:39:27 +0000
Subject: Sec Bug->Bug #63904 [Opn]: open_basedir is not respected for .user.ini files
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-234981@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=63904&edit=1 ID: 63904 Updated by: cmb@php.net Reported by: lekensteyn at gmail dot com Summary: open_basedir is not respected for .user.ini files Status: Open -Type: Security +Type: Bug Package: Safe Mode/open_basedir Operating System: Linux PHP Version: 5.4.10 Block user comment: N Private report: Y New Comment: open_basedir bypasses are not considered to be security issues; cf. <https://externals.io/message/105606> and <https://externals.io/message/115406>. Previous Comments: ------------------------------------------------------------------------ [2013-01-04 16:01:39] lekensteyn at gmail dot com Description: ------------ (this bug possibly applies to the CGI SAPI too, but I have not checked that.) In a default configuration for PHP-FPM, the use of .user.ini files is enabled. This feature allows you to put .user.ini interleaved with PHP files. There is a possibility to bypass open_basedir restrictions by using symlinks. For a given open_basedir = /foo/, a symlink /foo/.user.ini -> /bar/php.ini can be used to read the configuration of /bar/php.ini. It does not look like a feature, at first I wanted to have a .user.ini just outside the webroot (e.g. web/.user.ini with DOCUMENT_ROOT web/public_html), but having the symlink defeats the advantage of putting it outside the webroot for privacy. (ignoring WWW server abilities to restrict access). Therefore, it must be a bug that open_basedir is not respected for .user.ini files. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=63904&edit=1

« previous php.bugs (#234981) next »