Bug #11322 Updated: Security hole in multiuser environment

From: Date: Sun, 02 Jun 2002 17:39:08 +0000
Subject: Bug #11322 Updated: Security hole in multiuser environment
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-9171@lists.php.net to get a copy of this message
ID: 11322 Updated by: derick@php.net Reported By: wangshui@nyist.net -Status: Open +Status: Bogus Bug Type: Filesystem function related Operating System: Linux PHP Version: 4.0.4pl1 New Comment: Thank you for taking the time to report a problem with PHP. Unfortunately your version of PHP is too old -- the problem might already be fixed. Please download a new PHP version from http://www.php.net/downloads.php If you are able to reproduce the bug with one of the latest versions of PHP, please change the PHP version on this bug report to the version you tested and change the status back to "Open". Again, thank you for your continued support of PHP. Previous Comments: ------------------------------------------------------------------------ [2001-09-07 11:33:38] jflemer@php.net It looks like the 'copy' command has been patched to check source and destination in CVS. ------------------------------------------------------------------------ [2001-06-06 16:28:40] wangshui@nyist.net I'm a chinese user, and I give thousands of students websites with PHP-enabled within ONE machine. I found that: There ARE some security holes in multiuser environment for PHP concerning file system functions and directory funtions: 1.file-system functions such as 'fopen' are restricted by 'safe mode' and 'open_basedir', but 'copy' only checks the 'source' argument, not the 'destination', so one can copy his own scripts to someone else' directory and bypass the 'open_basedir' restriction. 2.'dir' class is not restricted by 'safe mode' or 'open_basedir'!!! 3.'chdir' is dangerous. one user can 'chdir' to another user's directory and access the files. ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=11322&edit=1

« previous php.bugs (#9171) next »