cvs: php4 /ext/standard/ filestat.c

From: Date: Fri, 09 Jun 2000 10:34:53 +0000
Subject: cvs: php4 /ext/standard/ filestat.c
Groups: php.cvs 
Request: Send a blank email to php-cvs+get-111@lists.php.net to get a copy of this message
stas Fri Jun 9 03:34:53 2000 EDT Modified files: /php4/ext/standard filestat.c Log: Make chmod in safe mode not allow SUID bits Index: php4/ext/standard/filestat.c diff -u php4/ext/standard/filestat.c:1.38 php4/ext/standard/filestat.c:1.39 --- php4/ext/standard/filestat.c:1.38 Mon Jun 5 12:47:44 2000 +++ php4/ext/standard/filestat.c Fri Jun 9 03:34:53 2000 @@ -16,7 +16,7 @@ +----------------------------------------------------------------------+ */ -/* $Id: filestat.c,v 1.38 2000/06/05 19:47:44 andi Exp $ */ +/* $Id: filestat.c,v 1.39 2000/06/09 10:34:53 stas Exp $ */ #include "php.h" #include "safe_mode.h" @@ -324,7 +324,7 @@ PHP_FUNCTION(chmod) { pval **filename, **mode; - int ret; + int ret,imode; PLS_FETCH(); if (ZEND_NUM_ARGS()!=2 || zend_get_parameters_ex(2,&filename,&mode)==FAILURE) { @@ -340,8 +340,16 @@ /* Check the basedir */ if (php_check_open_basedir((*filename)->value.str.val)) RETURN_FALSE; + + imode = (*mode)->value.lval; + /* in safe mode, do not allow to setuid files. + Setuiding files could allow users to gain privileges + that safe mode doesn't give them. + */ + if(PG(safe_mode)) + imode &= 0777; - ret = chmod((*filename)->value.str.val, (*mode)->value.lval); + ret = chmod((*filename)->value.str.val, imode); if (ret == -1) { php_error(E_WARNING, "chmod failed: %s", strerror(errno)); RETURN_FALSE;

« previous php.cvs (#111) next »