Bug #15547 Updated: tempnam() bypasses security
| From: | sander@php.net | Date: | Fri, 15 Feb 2002 18:08:10 +0000 |
| Subject: | Bug #15547 Updated: tempnam() bypasses security | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-386@lists.php.net to get a copy of this message | ||
ID: 15547
Updated by: sander@php.net
Reported By: temisu@utu.fi
-Status: Open
+Status: Feedback
Bug Type: Filesystem function related
Operating System: Linux(RedHat 7.1)
PHP Version: 4.0.6
New Comment:
Are you sure safe-mode is enabled?
Previous Comments:
------------------------------------------------------------------------
[2002-02-14 02:18:04] temisu@utu.fi
tempnam() function bypasses open_basedir directive
set by php.ini
This can be seen f.e. by following code:
$tfile=tempnam("/tmp","foobar");
// this is a success regardless of a open_basedir setting
$fp=fopen($tfile,"w")
// file is already created but fopen() fails if
// open_basedir is set, but not to include /tmp
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=15547&edit=1