cvs: php4 /ext/zip zip.c
| From: | Markus Fischer | Date: | Mon, 20 May 2002 18:33:09 +0000 |
| Subject: | cvs: php4 /ext/zip zip.c | ||
| Groups: | php.cvs | ||
| Request: | Send a blank email to php-cvs+get-12019@lists.php.net to get a copy of this message | ||
mfischer Mon May 20 14:33:09 2002 EDT
Modified files:
/php4/ext/zip zip.c
Log:
- Add safe_mode/uid and open_basedir check to zip_open() (closes #16927).
Index: php4/ext/zip/zip.c
diff -u php4/ext/zip/zip.c:1.31 php4/ext/zip/zip.c:1.32
--- php4/ext/zip/zip.c:1.31 Sun Apr 14 04:49:57 2002
+++ php4/ext/zip/zip.c Mon May 20 14:33:08 2002
@@ -16,7 +16,7 @@
+----------------------------------------------------------------------+
*/
-/* $Id: zip.c,v 1.31 2002/04/14 08:49:57 derick Exp $ */
+/* $Id: zip.c,v 1.32 2002/05/20 18:33:08 mfischer Exp $ */
#include "php.h"
#include "php_ini.h"
@@ -128,9 +128,18 @@
return;
}
+ if (PG(safe_mode) && (!php_checkuid(filename, NULL, CHECKUID_ALLOW_FILE_NOT_EXISTS))) {
+ RETURN_FALSE;
+ }
+
+ if (php_check_open_basedir(filename TSRMLS_CC)) {
+ RETURN_FALSE;
+ }
+
archive_p = zzip_opendir(filename);
if (archive_p == NULL) {
- php_error(E_WARNING, "Cannot open zip archive %s", filename);
+ php_error(E_WARNING, "%s() Cannot open zip archive %s",
+ get_active_function_name(TSRMLS_C), filename);
RETURN_FALSE;
}