Bug #15547 Updated: tempnam() bypasses security

From: Date: Fri, 15 Feb 2002 18:08:10 +0000
Subject: Bug #15547 Updated: tempnam() bypasses security
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-386@lists.php.net to get a copy of this message
ID: 15547 Updated by: sander@php.net Reported By: temisu@utu.fi -Status: Open +Status: Feedback Bug Type: Filesystem function related Operating System: Linux(RedHat 7.1) PHP Version: 4.0.6 New Comment: Are you sure safe-mode is enabled? Previous Comments: ------------------------------------------------------------------------ [2002-02-14 02:18:04] temisu@utu.fi tempnam() function bypasses open_basedir directive set by php.ini This can be seen f.e. by following code: $tfile=tempnam("/tmp","foobar"); // this is a success regardless of a open_basedir setting $fp=fopen($tfile,"w") // file is already created but fopen() fails if // open_basedir is set, but not to include /tmp ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=15547&edit=1

« previous php.bugs (#386) next »