Bug #11563 Updated: FileFunction macro in filestat.c appears to be missing a check (fix included)

From: Date: Mon, 20 May 2002 17:18:50 +0000
Subject: Bug #11563 Updated: FileFunction macro in filestat.c appears to be missing a check (fix included)
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-8004@lists.php.net to get a copy of this message
ID: 11563 Updated by: mfischer@php.net Reported By: henry@metroweb.co.za -Status: Open +Status: Closed Bug Type: Filesystem function related Operating System: linux 245 PHP Version: 4.0.5 New Comment: This bug has been fixed in CVS. You can grab a snapshot of the CVS version at http://snaps.php.net/. In case this was a documentation problem, the fix will show up soon at http://www.php.net/manual/. In case this was a PHP.net website problem, the change will show up on the PHP.net site and on the mirror sites. Thank you for the report, and for helping us make PHP better. Previous Comments: ------------------------------------------------------------------------ [2001-06-19 12:16:36] henry@metroweb.co.za safe_mode off open_basedir in effect disable_functions=system exec passthru chmod,...etc... For ISPs safe_mode is too limiting; we use open_basedir extensively. However, many is_* functions and all function calls which use the FileFunction macro in filestat.c ignore the open_basedir restriction completely (the only way around this of course is to disable all those useful funcs). Fix follows: Add this line after convert_to_string_ex(filename); \ in filestat.c (about line 628): if (php_check_open_basedir((*filename)->value.str.val)) RETURN_FALSE; \ ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=11563&edit=1

« previous php.bugs (#8004) next »