#23278 [Opn->Csd]: safe_mode too strict at show_source()
| From: | sniper@php.net | Date: | Mon, 21 Apr 2003 17:33:30 +0000 |
| Subject: | #23278 [Opn->Csd]: safe_mode too strict at show_source() | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-37995@lists.php.net to get a copy of this message | ||
ID: 23278
Updated by: sniper@php.net
Reported By: adrian at planetcoding dot net
-Status: Open
+Status: Closed
Bug Type: *General Issues
Operating System: SuSE Linux 8.1 w/ Confixx 2 pro
PHP Version: 4.3.1
New Comment:
This bug has been fixed in CVS.
In case this was a PHP problem, snapshots of the sources are packaged
every three hours; this change will be in the next snapshot. You can
grab the snapshot at http://snaps.php.net/.
In case this was a documentation problem, the fix will show up soon at
http://www.php.net/manual/.
In case this was a PHP.net website problem, the change will show
up on the PHP.net site and on the mirror sites in short time.
Thank you for the report, and for helping us make PHP better.
Now fopen() also honors the safe-mode.
Previous Comments:
------------------------------------------------------------------------
[2003-04-21 10:40:31] adrian at planetcoding dot net
ps: the file was uploaded via HTTP upload and moved to ./files with
move_uploaded_file()
------------------------------------------------------------------------
[2003-04-21 10:24:20] adrian at planetcoding dot net
[status set to open again]
------------------------------------------------------------------------
[2003-04-21 10:18:26] adrian at planetcoding dot net
this code:
__________________________
ob_start();
show_source("files/".$version_info['version_id'].ifelse($file_info['extension'],".".$file_info['extension']));
$source = ob_get_contents();
ob_end_clean();
__________________________
throws this error: Warning: show_source() [function.show-source.html]:
SAFE MODE Restriction in effect. The script whose uid is 641 is not
allowed to access files/21.php owned by uid 30 in
/home/www/web5/html/browse.php on line 240
this code (and any other file operations) works:
__________________________
ob_start();
$fp=fopen("files/".$version_info['version_id'].ifelse($file_info['extension'],".".$file_info['extension']),'r');
$source =
fread($fp,filesize("files/".$version_info['version_id'].ifelse($file_info['extension'],".".$file_info['extension'])));
highlight_string($source);
$source = ob_get_contents();
ob_end_clean();
__________________________
------------------------------------------------------------------------
[2003-04-21 09:58:00] sniper@php.net
Not enough information was provided for us to be able
to handle this bug. Please re-read the instructions at
http://bugs.php.net/how-to-report.php
If you can provide more information, feel free to add it
to this bug and change the status back to "Open".
Thank you for your interest in PHP.
.
------------------------------------------------------------------------
[2003-04-19 06:03:01] adrian at planetcoding dot net
The safe_mode seems to be too strict when using show_source:
PHP can delete a uploaded file which is owned by the webserver, kan
read it w/ fopen or readfile, can do anything with it except of
show_source.
I just get the safe_mode restriction in effect... - message.
If I use fopen and highlight_string, it works fine.
./configure:
'./configure' '--prefix=/usr/share' '--bindir=/usr/bin'
'--libdir=/usr/lib' '--datadir=/usr/share/php'
'--includedir=/usr/include' '--with-apxs=/usr/sbin/apxs'
'--enable-force-cgi-redirect' '--with-config-file-path=/etc'
'--with-openssl' '--with-zlib' '--enable-bcmath'
'--with-bz2'
'--enable-calendar' '--with-curl' '--enable-exif'
'--enable-ftp'
'--with-gd' '--enable-gd-native-ttf' '--enable-gd-imgstrttf'
'--with-gettext' '--with-iconv' '--enable-mbstring'
'--enable-mbregex'
'--with-mcal' '--with-mcrypt' '--with-mhash' '--with-ming'
'--with-mysql' '--with-ncurses' '--with-pdflib'
'--with-readline'
'--enable-shmop' '--enable-sysvsem' '--enable-sysvshm'
'--enable-wddx'
'--enable-versioning' '--with-xml' '--enable-ctype'
phpinfo: http://www.planetcoding-server.net/phpinfo.php
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=23278&edit=1