cvs: php4 /ext/standard/ filestat.c
| From: | Stanislav Malyshev | Date: | Fri, 09 Jun 2000 10:34:53 +0000 |
| Subject: | cvs: php4 /ext/standard/ filestat.c | ||
| Groups: | php.cvs | ||
| Request: | Send a blank email to php-cvs+get-111@lists.php.net to get a copy of this message | ||
stas Fri Jun 9 03:34:53 2000 EDT
Modified files:
/php4/ext/standard filestat.c
Log:
Make chmod in safe mode not allow SUID bits
Index: php4/ext/standard/filestat.c
diff -u php4/ext/standard/filestat.c:1.38 php4/ext/standard/filestat.c:1.39
--- php4/ext/standard/filestat.c:1.38 Mon Jun 5 12:47:44 2000
+++ php4/ext/standard/filestat.c Fri Jun 9 03:34:53 2000
@@ -16,7 +16,7 @@
+----------------------------------------------------------------------+
*/
-/* $Id: filestat.c,v 1.38 2000/06/05 19:47:44 andi Exp $ */
+/* $Id: filestat.c,v 1.39 2000/06/09 10:34:53 stas Exp $ */
#include "php.h"
#include "safe_mode.h"
@@ -324,7 +324,7 @@
PHP_FUNCTION(chmod)
{
pval **filename, **mode;
- int ret;
+ int ret,imode;
PLS_FETCH();
if (ZEND_NUM_ARGS()!=2 || zend_get_parameters_ex(2,&filename,&mode)==FAILURE) {
@@ -340,8 +340,16 @@
/* Check the basedir */
if (php_check_open_basedir((*filename)->value.str.val))
RETURN_FALSE;
+
+ imode = (*mode)->value.lval;
+ /* in safe mode, do not allow to setuid files.
+ Setuiding files could allow users to gain privileges
+ that safe mode doesn't give them.
+ */
+ if(PG(safe_mode))
+ imode &= 0777;
- ret = chmod((*filename)->value.str.val, (*mode)->value.lval);
+ ret = chmod((*filename)->value.str.val, imode);
if (ret == -1) {
php_error(E_WARNING, "chmod failed: %s", strerror(errno));
RETURN_FALSE;