#23349 [Opn->Fbk]: safe_mode file UID check not functional when directory owned by user

From: Date: Fri, 25 Apr 2003 22:03:28 +0000
Subject: #23349 [Opn->Fbk]: safe_mode file UID check not functional when directory owned by user
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-38418@lists.php.net to get a copy of this message
ID: 23349 Updated by: sniper@php.net Reported By: gk at proliberty dot com -Status: Open +Status: Feedback -Bug Type: *General Issues +Bug Type: Filesystem function related Operating System: linux PHP Version: 4.3.2RC1 New Comment: Please try using this CVS snapshot: http://snaps.php.net/php4-STABLE-latest.tar.gz For Windows: http://snaps.php.net/win32/php4-win32-STABLE-latest.zip Previous Comments: ------------------------------------------------------------------------ [2003-04-25 14:06:29] gk at proliberty dot com The output below illustrates this problem: safe_mode UID check is not applied to a file not owned by the user if the user owns the directory iin which it resides. I have not tested to see if this problem is reproducible under other than SAPI/CLI. My php.ini is 'php.ini-recommended'. open_basedir is not set. [greg@p3 safe]$ php -v PHP 4.3.2-RC (cli) (built: Mar 24 2003 12:27:32) [greg@p3 safe]$ cat safe.junk hi [greg@p3 safe]$ ls -al total 12 drwxr-xr-x 2 greg greg 4096 Apr 25 11:48 . drwxrwxr-x 9 greg greg 4096 Apr 25 11:48 .. -rw-r--r-- 1 root root 3 Apr 25 11:46 safe.junk [greg@p3 safe]$ ls -al [greg@p3 safe]$ whoami greg [greg@p3 safe]$ php -d safe_mode=1 -r 'readfile("safe.junk");' hi [greg@p3 safe]$ php -d safe_mode=1 -r 'readfile("/etc/passwd");' PHP Warning: readfile(): SAFE MODE Restriction in effect. The script whose uid is 500 is not allowed to access /etc/passwd owned by uid 0 in Command line code on line 1 PHP Warning: readfile(/etc/passwd): failed to open stream: No such file or directory in Command line code on line 1 [greg@p3 safe]$ cd .. [greg@p3 junk]$ su Password: [root@p3 junk]# chown root:root safe [root@p3 junk]# exit exit [greg@p3 junk]$ cd safe [greg@p3 safe]$ php -d safe_mode=1 -r 'readfile("safe.junk");' PHP Warning: readfile(): SAFE MODE Restriction in effect. The script whose uid is 500 is not allowed to access safe.junk owned by uid 0 in Command line code on line 1 PHP Warning: readfile(safe.junk): failed to open stream: No such file or directory in Command line code on line 1 ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=23349&edit=1

« previous php.bugs (#38418) next »