#23278 [Opn->Csd]: safe_mode too strict at show_source()

From: Date: Mon, 21 Apr 2003 17:33:30 +0000
Subject: #23278 [Opn->Csd]: safe_mode too strict at show_source()
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-37995@lists.php.net to get a copy of this message
ID: 23278 Updated by: sniper@php.net Reported By: adrian at planetcoding dot net -Status: Open +Status: Closed Bug Type: *General Issues Operating System: SuSE Linux 8.1 w/ Confixx 2 pro PHP Version: 4.3.1 New Comment: This bug has been fixed in CVS. In case this was a PHP problem, snapshots of the sources are packaged every three hours; this change will be in the next snapshot. You can grab the snapshot at http://snaps.php.net/. In case this was a documentation problem, the fix will show up soon at http://www.php.net/manual/. In case this was a PHP.net website problem, the change will show up on the PHP.net site and on the mirror sites in short time. Thank you for the report, and for helping us make PHP better. Now fopen() also honors the safe-mode. Previous Comments: ------------------------------------------------------------------------ [2003-04-21 10:40:31] adrian at planetcoding dot net ps: the file was uploaded via HTTP upload and moved to ./files with move_uploaded_file() ------------------------------------------------------------------------ [2003-04-21 10:24:20] adrian at planetcoding dot net [status set to open again] ------------------------------------------------------------------------ [2003-04-21 10:18:26] adrian at planetcoding dot net this code: __________________________ ob_start(); show_source("files/".$version_info['version_id'].ifelse($file_info['extension'],".".$file_info['extension'])); $source = ob_get_contents(); ob_end_clean(); __________________________ throws this error: Warning: show_source() [function.show-source.html]: SAFE MODE Restriction in effect. The script whose uid is 641 is not allowed to access files/21.php owned by uid 30 in /home/www/web5/html/browse.php on line 240 this code (and any other file operations) works: __________________________ ob_start(); $fp=fopen("files/".$version_info['version_id'].ifelse($file_info['extension'],".".$file_info['extension']),'r'); $source = fread($fp,filesize("files/".$version_info['version_id'].ifelse($file_info['extension'],".".$file_info['extension']))); highlight_string($source); $source = ob_get_contents(); ob_end_clean(); __________________________ ------------------------------------------------------------------------ [2003-04-21 09:58:00] sniper@php.net Not enough information was provided for us to be able to handle this bug. Please re-read the instructions at http://bugs.php.net/how-to-report.php If you can provide more information, feel free to add it to this bug and change the status back to "Open". Thank you for your interest in PHP. . ------------------------------------------------------------------------ [2003-04-19 06:03:01] adrian at planetcoding dot net The safe_mode seems to be too strict when using show_source: PHP can delete a uploaded file which is owned by the webserver, kan read it w/ fopen or readfile, can do anything with it except of show_source. I just get the safe_mode restriction in effect... - message. If I use fopen and highlight_string, it works fine. ./configure: './configure' '--prefix=/usr/share' '--bindir=/usr/bin' '--libdir=/usr/lib' '--datadir=/usr/share/php' '--includedir=/usr/include' '--with-apxs=/usr/sbin/apxs' '--enable-force-cgi-redirect' '--with-config-file-path=/etc' '--with-openssl' '--with-zlib' '--enable-bcmath' '--with-bz2' '--enable-calendar' '--with-curl' '--enable-exif' '--enable-ftp' '--with-gd' '--enable-gd-native-ttf' '--enable-gd-imgstrttf' '--with-gettext' '--with-iconv' '--enable-mbstring' '--enable-mbregex' '--with-mcal' '--with-mcrypt' '--with-mhash' '--with-ming' '--with-mysql' '--with-ncurses' '--with-pdflib' '--with-readline' '--enable-shmop' '--enable-sysvsem' '--enable-sysvshm' '--enable-wddx' '--enable-versioning' '--with-xml' '--enable-ctype' phpinfo: http://www.planetcoding-server.net/phpinfo.php ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=23278&edit=1

« previous php.bugs (#37995) next »