#15375 [Opn->Csd]: safe_mode wrappers fail for MySQL (other exts?)

From: Date: Thu, 24 Apr 2003 09:21:01 +0000
Subject: #15375 [Opn->Csd]: safe_mode wrappers fail for MySQL (other exts?)
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-38283@lists.php.net to get a copy of this message
 ID:               15375
 Updated by:       georg@php.net
 Reported By:      matslin at orakel dot ntnu dot no
-Status:           Open
+Status:           Closed
 Bug Type:         MySQL related
 Operating System: All
 PHP Version:      4.1.1
 Assigned To:      zak
 New Comment:

This problem is already closed. Bundled libmysql doesn't support local
anymore.


Previous Comments:
------------------------------------------------------------------------

[2002-09-19 23:14:55] zak@php.net

I should re-examine this one as well. 

------------------------------------------------------------------------

[2002-02-10 14:18:35] zak@php.net

A fix for this behavior should appear within the next few 
releases of the MySQL 4.0.x series.

I will update this bug when the fix is implemented.


------------------------------------------------------------------------

[2002-02-05 12:24:48] matslin at orakel dot ntnu dot no

I generally agree on Rasmus' feedback on the issue, so i'll leave it
closed. However, since this naturally works with remote mysql-servers,
setting up a server where you have the create-permission isnt really
much of a hazzle.

------------------------------------------------------------------------

[2002-02-05 10:15:39] vitek at zoner dot com

It works even if you are connecting to remote mysql server over tcp/ip,
so I don't think this is only mysql related issue.

------------------------------------------------------------------------

[2002-02-05 09:53:36] zak@php.net

Verified that the exploit allows any file readable by the 
MySQL server to be viewed via this technique. Note that 
forbidding the MySQL user CREATE permission does make the 
exploit less convenient for the attacker.

The MySQL dev team is looking at ways to reduce this risk 
via MySQL permission behavior in the server.

Given Rasmus' feedback on the issue, I am closing this as 
a PHP bug. Hopefully, the MySQL dev team should be able 
eliminate or reduce this risk. If we can't completely 
resolve it, I will re-examine this bug.

--zak@[mysql|php].com


------------------------------------------------------------------------

The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
    http://bugs.php.net/15375

-- 
Edit this bug report at http://bugs.php.net/?id=15375&edit=1



Thread (1 message)

  • georg@php.net
  • Unknown Message
    • georg@php.net
« previous php.bugs (#38283) next »