#12255 [Com]: (In safe mode) The UID check in chdir don't test the good directory
| From: | sex-world1932 at hotmail dot com | Date: | Tue, 20 Jul 2004 15:11:01 +0000 |
| Subject: | #12255 [Com]: (In safe mode) The UID check in chdir don't test the good directory | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-63167@lists.php.net to get a copy of this message | ||
ID: 12255
Comment by: sex-world1932 at hotmail dot com
Reported By: benoit at proxad dot net
Status: Closed
Bug Type: Directory function related
Operating System: Debian GNU/Linux sid
PHP Version: 4.0.6
New Comment:
<a href=http://r-special-shemalemp.da.ru>world
sex</a>
Previous Comments:
------------------------------------------------------------------------
[2001-07-26 21:38:03] sniper@php.net
fixed -> closed.
------------------------------------------------------------------------
[2001-07-19 16:20:32] jflemer@php.net
I fixed this in CVS. This is a duplicate bug report.
------------------------------------------------------------------------
[2001-07-19 10:55:20] benoit at proxad dot net
In safe mode, when you chdir a specific directory, it does not test the
UID of directory but the UID of the directory below.
Let's say we do a chdir ("/home/benoit");
In safe mode, it will test the UID of /home against the one of the
script so it fails.
If we do a chdir ("/home/benoit/."); , PHP test the UID of
/home/benoit/ against the UID of the script and succeed.
But, logically, the two commands should succeed the same way.
I think it's related to the code in "ext/standard/dir.c" around line
286 :
> if (PG(safe_mode) && !php_checkuid((*arg)->value.str.val, NULL,
CHECKUID_ALLOW_ONLY_DIR)) {
and the way php_checkuid handle CHECKUID_ALLOW_ONLY_DIR.
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=12255&edit=1