#21356 [Opn->WFx]: LOAD DATA issue

From: Date: Thu, 24 Apr 2003 09:16:43 +0000
Subject: #21356 [Opn->WFx]: LOAD DATA issue
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-38280@lists.php.net to get a copy of this message
ID: 21356 Updated by: georg@php.net Reported By: michael at tapinternet dot com -Status: Open +Status: Wont fix Bug Type: MySQL related Operating System: Slackware PHP Version: 4.3.0 New Comment: It's not a bug, it's a feature :) We will not change this in PHP4 anymore, it's already on TODO for ext/mysql and ext/mysqli in PHP5. If you need LOAD DATA LOCAL INFILE (and LOAD DATA INFILE doesn't work for you), use an external mysql library. Previous Comments: ------------------------------------------------------------------------ [2003-02-03 19:26:08] rlm at pricegrabber dot com This "security patch" is extremely dubious on MySQL clients standalone, much less PHP. It purports to prevent patched MySQL clients/servers from causing problems by reading local files, but if you have a patched MySQL server, you have a much, much worse problem than remote file reads. Besides, if you can read arbitrary files using MySQL, you can do the same for PHP. This should have never entered the code stream, and really ought to be disabled (it's turned off by default in 3.23.49a and subsequent). ------------------------------------------------------------------------ [2003-02-01 14:27:42] brunofr at ioda-net dot ch This bug is found and test with W2K and NT4.0 PhP 4.3.0 Try with Mysql 3.23.53 - 3.23.54 - 3.23.55 Was not present PhP version before ( 4.2.4-dev snapshot from the 24 October 2002 Why this bug ??? Is there a lack in Quality Test... found this in the news.txt disto - Fixed a security bug in the bundled MySQL library. (Georg, Stefan) question why 3.23.49 client version as Mysql released very more up to date lib at the build 4.3. date. Could this be corrected in the snapshot-stable version. Thank ... have lost to much time today with this. ------------------------------------------------------------------------ [2003-01-29 14:59:16] billk at iinet dot net dot au "BASE" microarray software requires this function. On gentoo I had to build mysql first after adding the flag, then rebuild php to get the functionality included. ------------------------------------------------------------------------ [2003-01-02 17:53:01] michael at tapinternet dot com Didn't try that specifically, but the problem does not exist if I use mysql from the command line. I 'solved' this for my immediate situation by removing the 'if' around the infile check in ext/mysql/libmysql/libmysql.c Here (line 1025?): /* Only enable LOAD DATA INFILE by default if configured with --with-enabled-local-inflile */ #ifdef ENABLED_LOCAL_INFILE mysql->options.client_flag|= CLIENT_LOCAL_FILES; #endif return mysql; is now: /* Only enable LOAD DATA INFILE by default if configured with --with-enabled-local-inflile */ mysql->options.client_flag|= CLIENT_LOCAL_FILES; return mysql; recompiled everything and it works. I'd tried to recompile PHP with '--with-enabled-local-inflile' (and the properly spelled '--with-enabled-local-infile') and neither worked. The only thing that worked was removing the IF stuff in the .c file. ------------------------------------------------------------------------ [2003-01-02 17:26:10] iliaa@php.net Does the problem go away if you tell PHP to use your MySQL's headers rather then the ones bundled with PHP? ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at http://bugs.php.net/21356 -- Edit this bug report at http://bugs.php.net/?id=21356&edit=1

« previous php.bugs (#38280) next »