#36223 [NEW]: curl bypasses open_basedir restrictions

From: Date: Tue, 31 Jan 2006 10:19:02 +0000
Subject: #36223 [NEW]: curl bypasses open_basedir restrictions
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-92684@lists.php.net to get a copy of this message
From: stevewest15 at yahoo dot com Operating system: Redhat Enterprise 3.6 PHP version: 4.4.2 PHP Bug Type: Safe Mode/open_basedir Bug description: curl bypasses open_basedir restrictions Description: ------------ PHP 4.4.2 still has the bug which allows CURL to bypass open_basedir restrictions. Your release notes for 4.4.2 state that it has been fixed...but it hasn't! :-( Here is the configure line for PHP: './configure' '--localstatedir=/var/hsphere/php' '--with-apxs=/hsphere/shared/apache/bin/apxs' '--with-openssl=/usr' '--with-zlib=/usr' '--with-zlib-dir=/usr' '--with-bz2=/usr' '--enable-calendar' '--with-jpeg-dir=/hsphere/shared' '--enable-ftp' '--with-gd' '--with-ttf' '--with-freetype-dir=/hsphere/shared' '--enable-gd-native-ttf' '--with-png-dir=/hsphere/shared' '--with-gettext=/hsphere/shared' '--with-imap=/hsphere/shared' '--with-mysql=//usr' '--with-pgsql=//usr' '--with-curl=/hsphere/shared' '--with-curlwrappers' '--with-mhash=/hsphere/shared' '--with-mcrypt=/hsphere/shared' '--with-iconv=/hsphere/shared' '--enable-sockets' '--with-zip=/hsphere/shared' '--enable-versioning' '--enable-track-vars' '--enable-trans-sid' '--enable-bcmath' '--enable-mbstring' '--disable-debug' '--enable-pspell' '--enable-memory-limit' '--disable-files' Changes to php.ini made: open_basedir = /home/hsphere/shared/apache/htdocs/:/usr/local/lib/php/:/tmp/ disable_functions = "pack,system" Please fix this Reproduce code: --------------- <?php $ch = curl_init("file:/etc/snmp/snmpd.conf"); $file=curl_exec($ch); echo $file ?> Expected result: ---------------- It should say that open_basedir restrictions are in affect and that it couldn't retrieve file. Actual result: -------------- When the above code is run, it actually retrieves my /etc/snmpd.conf and displays it's content in my browser. BIG SECURITY concern! -- Edit bug report at http://bugs.php.net/?id=36223&edit=1 -- Try a CVS snapshot (PHP 4.4): http://bugs.php.net/fix.php?id=36223&r=trysnapshot44 Try a CVS snapshot (PHP 5.1): http://bugs.php.net/fix.php?id=36223&r=trysnapshot51 Try a CVS snapshot (PHP 6.0): http://bugs.php.net/fix.php?id=36223&r=trysnapshot60 Fixed in CVS: http://bugs.php.net/fix.php?id=36223&r=fixedcvs Fixed in release: http://bugs.php.net/fix.php?id=36223&r=alreadyfixed Need backtrace: http://bugs.php.net/fix.php?id=36223&r=needtrace Need Reproduce Script: http://bugs.php.net/fix.php?id=36223&r=needscript Try newer version: http://bugs.php.net/fix.php?id=36223&r=oldversion Not developer issue: http://bugs.php.net/fix.php?id=36223&r=support Expected behavior: http://bugs.php.net/fix.php?id=36223&r=notwrong Not enough info: http://bugs.php.net/fix.php?id=36223&r=notenoughinfo Submitted twice: http://bugs.php.net/fix.php?id=36223&r=submittedtwice register_globals: http://bugs.php.net/fix.php?id=36223&r=globals PHP 3 support discontinued: http://bugs.php.net/fix.php?id=36223&r=php3 Daylight Savings: http://bugs.php.net/fix.php?id=36223&r=dst IIS Stability: http://bugs.php.net/fix.php?id=36223&r=isapi Install GNU Sed: http://bugs.php.net/fix.php?id=36223&r=gnused Floating point limitations: http://bugs.php.net/fix.php?id=36223&r=float No Zend Extensions: http://bugs.php.net/fix.php?id=36223&r=nozend MySQL Configuration Error: http://bugs.php.net/fix.php?id=36223&r=mysqlcfg

« previous php.bugs (#92684) next »