#23236 [Bgs]: move_uploaded_file corrupts images
| From: | dan at GARBAGE dot highspeedlink dot net | Date: | Tue, 22 Apr 2003 21:27:19 +0000 |
| Subject: | #23236 [Bgs]: move_uploaded_file corrupts images | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-38090@lists.php.net to get a copy of this message | ||
ID: 23236
User updated by: dan at GARBAGE dot highspeedlink dot net
Reported By: dan at GARBAGE dot highspeedlink dot net
Status: Bogus
Bug Type: *General Issues
Operating System: Linux 2.4.18-14 RedHat 8
PHP Version: 4.3.1
New Comment:
<P>Thanks, sniper, very helpful. Ooh, let's see, do I:</P>
<P><OL><LI>Change the <I>./configure</I> options for PHP?</LI>
<LI>Modify <I>httpd.conf</I> in some way?</I></LI>
<LI>Recompile my kernel?</LI></OL>
or, secret option number four:<BR>
Do whatever I'm doing wrong, <I>differently</I>.</P>
<B>Great</B> idea, buddy. Where do I sign up?</P>
<P>Does anybody have any <U>real</U> suggestions for how to go about
fixing this?</P>
Previous Comments:
------------------------------------------------------------------------
[2003-04-21 12:37:00] sniper@php.net
You're doing something wrong.
------------------------------------------------------------------------
[2003-04-17 13:13:02] dan at GARBAGE dot highspeedlink dot net
My apologies--FollowSymLinks got smashed in the config at some point.
See if you can see any obvious problems before I recompile PHP yet
again, please?
PHPInfo page added at http://admin.highspeedlink.net/PHP/info.php
for
your edification.
------------------------------------------------------------------------
[2003-04-17 01:16:22] magnus@php.net
Please try using this CVS snapshot:
http://snaps.php.net/php4-STABLE-latest.tar.gz
For Windows:
http://snaps.php.net/win32/php4-win32-STABLE-latest.zip
and that link to the source code of the script gives a
permission denied error.
------------------------------------------------------------------------
[2003-04-16 02:16:33] dan at GARBAGE dot highspeedlink dot net
(remove GARBAGE to reply, or it gets feed into the spamtrap)
Can anybody explain what's happening to perfectly good images passing
through http://admin.highspeedlink.net/PHP/ for
me? The code for the
page is available at http://admin.highspeedlink.net/PHP/source.txt
for
your perusal. I've tested with MSIE 6.0 and Mozilla 1.4a on Windows,
so this doesn't seem to be browser-specific. Also, running dos2unix,
unix2dos, etc. doesn't seem to help.
Considering what suggestions I've seen thus far, I'm thinking this is a
bug, possibly related to character encoding, in move_uploaded_file().
Can people test this out and see how deadly it really is?
Warning for the squeamish: the linked page allows uploading of
arbitrary images up to 100 [decimal] KB in size, and displays the last
uploaded image. No promises on what will or won't be there when you
look. Just upload only pictures of
http://www.google.com/images?q=flowers and
such, okay? Feel free to
upload arbitrary binary data and access it directly, as well--no
filetype restrictions are in place.
This is not a localized copy of Apache, and thus #11066 does not apply.
(Indeed, my Apache 2.0.43 doesn't even recognize the
CharsetRecodeMultipartForm directive.)
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=23236&edit=1