#21356 [Opn->WFx]: LOAD DATA issue
| From: | georg@php.net | Date: | Thu, 24 Apr 2003 09:16:43 +0000 |
| Subject: | #21356 [Opn->WFx]: LOAD DATA issue | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-38280@lists.php.net to get a copy of this message | ||
ID: 21356
Updated by: georg@php.net
Reported By: michael at tapinternet dot com
-Status: Open
+Status: Wont fix
Bug Type: MySQL related
Operating System: Slackware
PHP Version: 4.3.0
New Comment:
It's not a bug, it's a feature :)
We will not change this in PHP4 anymore, it's already on TODO for
ext/mysql and ext/mysqli in PHP5.
If you need LOAD DATA LOCAL INFILE (and LOAD DATA INFILE doesn't work
for you), use an external mysql library.
Previous Comments:
------------------------------------------------------------------------
[2003-02-03 19:26:08] rlm at pricegrabber dot com
This "security patch" is extremely dubious on MySQL clients standalone,
much less PHP. It purports to prevent patched MySQL clients/servers
from causing problems by reading local files, but if you have a patched
MySQL server, you have a much, much worse problem than remote file
reads. Besides, if you can read arbitrary files using MySQL, you can
do the same for PHP. This should have never entered the code stream,
and really ought to be disabled (it's turned off by default in 3.23.49a
and subsequent).
------------------------------------------------------------------------
[2003-02-01 14:27:42] brunofr at ioda-net dot ch
This bug is found and test with W2K and NT4.0
PhP 4.3.0
Try with Mysql 3.23.53 - 3.23.54 - 3.23.55
Was not present PhP version before ( 4.2.4-dev snapshot from the 24
October 2002
Why this bug ???
Is there a lack in Quality Test...
found this in the news.txt disto
- Fixed a security bug in the bundled MySQL library. (Georg, Stefan)
question why 3.23.49 client version as Mysql released very more up to
date lib at the build 4.3. date.
Could this be corrected in the snapshot-stable version.
Thank ... have lost to much time today with this.
------------------------------------------------------------------------
[2003-01-29 14:59:16] billk at iinet dot net dot au
"BASE" microarray software requires this function. On gentoo I had to
build mysql first after adding the flag, then rebuild php to get the
functionality included.
------------------------------------------------------------------------
[2003-01-02 17:53:01] michael at tapinternet dot com
Didn't try that specifically, but the problem does not exist if I use
mysql from the command line.
I 'solved' this for my immediate situation by removing the 'if' around
the infile check in ext/mysql/libmysql/libmysql.c
Here (line 1025?):
/*
Only enable LOAD DATA INFILE by default if configured with
--with-enabled-local-inflile
*/
#ifdef ENABLED_LOCAL_INFILE
mysql->options.client_flag|= CLIENT_LOCAL_FILES;
#endif
return mysql;
is now:
/*
Only enable LOAD DATA INFILE by default if configured with
--with-enabled-local-inflile
*/
mysql->options.client_flag|= CLIENT_LOCAL_FILES;
return mysql;
recompiled everything and it works.
I'd tried to recompile PHP with '--with-enabled-local-inflile' (and the
properly spelled '--with-enabled-local-infile') and neither worked.
The only thing that worked was removing the IF stuff in the .c file.
------------------------------------------------------------------------
[2003-01-02 17:26:10] iliaa@php.net
Does the problem go away if you tell PHP to use your MySQL's headers
rather then the ones bundled with PHP?
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
http://bugs.php.net/21356
--
Edit this bug report at http://bugs.php.net/?id=21356&edit=1