Sec Bug->Bug #63904 [Opn]: open_basedir is not respected for .user.ini files
| From: | cmb@php.net | Date: | Mon, 12 Jul 2021 15:39:27 +0000 |
| Subject: | Sec Bug->Bug #63904 [Opn]: open_basedir is not respected for .user.ini files | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-234981@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=63904&edit=1
ID: 63904
Updated by: cmb@php.net
Reported by: lekensteyn at gmail dot com
Summary: open_basedir is not respected for .user.ini files
Status: Open
-Type: Security
+Type: Bug
Package: Safe Mode/open_basedir
Operating System: Linux
PHP Version: 5.4.10
Block user comment: N
Private report: Y
New Comment:
open_basedir bypasses are not considered to be security issues;
cf. <https://externals.io/message/105606>
and <https://externals.io/message/115406>.
Previous Comments:
------------------------------------------------------------------------
[2013-01-04 16:01:39] lekensteyn at gmail dot com
Description:
------------
(this bug possibly applies to the CGI SAPI too, but I have not checked that.)
In a default configuration for PHP-FPM, the use of .user.ini files is enabled. This feature allows
you to put .user.ini interleaved with PHP files.
There is a possibility to bypass open_basedir restrictions by using symlinks. For a given
open_basedir = /foo/, a symlink /foo/.user.ini -> /bar/php.ini can be used to read the
configuration of /bar/php.ini.
It does not look like a feature, at first I wanted to have a .user.ini just outside the webroot
(e.g. web/.user.ini with DOCUMENT_ROOT web/public_html), but having the symlink defeats the
advantage of putting it outside the webroot for privacy. (ignoring WWW server abilities to restrict
access). Therefore, it must be a bug that open_basedir is not respected for .user.ini files.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=63904&edit=1