Bug #15547 Updated: tempnam() bypasses security
| From: | rasmus@php.net | Date: | Wed, 20 Feb 2002 20:37:24 +0000 |
| Subject: | Bug #15547 Updated: tempnam() bypasses security | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-682@lists.php.net to get a copy of this message | ||
ID: 15547
Updated by: rasmus@php.net
Reported By: temisu@utu.fi
-Status: Bogus
+Status: Open
Bug Type: Filesystem function related
Operating System: Linux(RedHat 7.1)
PHP Version: 4.0.6
New Comment:
open_basedir is completely separate from safe_mode so this is actually
a bug.
Previous Comments:
------------------------------------------------------------------------
[2002-02-19 01:10:53] temisu@utu.fi
document
http://www.php.net/manual/en/features.safe-mode.php
says that
If instead of safe_mode, you set an open_basedir directory
^^^^^^^
then all file operations will be limited to files under the specified
directory For example (Apache httpd.conf example):
------------------------------------------------------------------------
[2002-02-18 10:20:29] sander@php.net
AFAIK, open_basedir restrictions only _work_ when having safe_mode ON.
------------------------------------------------------------------------
[2002-02-18 01:44:15] temisu@utu.fi
> Are you sure safe-mode is enabled?
No it is not. open_basedir seems to be independent directive
without connection to the safe-mode (Atleast, the directory
restrictions work on other file-operations but not tempnam)
The following is example what triggered this in my code.
php.ini has open_basedir=/www/htdocs and safe_mode= off
The working code...
$tfile=tempnam("/www/htdocs/tmp","foobar");
// success if /www/htdocs/tmp/ exists and is writable
// directory
$fp=fopen($tfile,"w");
// opens the file.
The initial version, which does not care about the
open_basedir...
$tfile=tempnam("/tmp","foobar");
// creates the temp-file.
$fp=fopen($tfile,"w");
// tries to open the file but does not succeed because of
// the open_basedir setting!
//
// Because (any other) file operations cannot be used on /tmp
// this code clutters the /tmp directory with zerobyte
// temp-files.
------------------------------------------------------------------------
[2002-02-15 13:08:10] sander@php.net
Are you sure safe-mode is enabled?
------------------------------------------------------------------------
[2002-02-14 02:18:04] temisu@utu.fi
tempnam() function bypasses open_basedir directive
set by php.ini
This can be seen f.e. by following code:
$tfile=tempnam("/tmp","foobar");
// this is a success regardless of a open_basedir setting
$fp=fopen($tfile,"w")
// file is already created but fopen() fails if
// open_basedir is set, but not to include /tmp
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=15547&edit=1