cvs: php4(PHP_4_2_0) /ext/standard link.c
| From: | Stefan Esser | Date: | Sun, 23 Jun 2002 17:18:17 +0000 |
| Subject: | cvs: php4(PHP_4_2_0) /ext/standard link.c | ||
| Groups: | php.cvs | ||
| Request: | Send a blank email to php-cvs+get-12464@lists.php.net to get a copy of this message | ||
sesser Sun Jun 23 13:18:17 2002 EDT
Modified files: (Branch: PHP_4_2_0)
/php4/ext/standard link.c
Log:
MFH: link/symlink safe_mode/open_base_dir fix
Index: php4/ext/standard/link.c
diff -u php4/ext/standard/link.c:1.37 php4/ext/standard/link.c:1.37.2.1
--- php4/ext/standard/link.c:1.37 Thu Feb 28 03:26:46 2002
+++ php4/ext/standard/link.c Sun Jun 23 13:18:17 2002
@@ -16,7 +16,7 @@
+----------------------------------------------------------------------+
*/
-/* $Id: link.c,v 1.37 2002/02/28 08:26:46 sebastian Exp $ */
+/* $Id: link.c,v 1.37.2.1 2002/06/23 17:18:17 sesser Exp $ */
#include "php.h"
#include "php_filestat.h"
@@ -114,6 +114,18 @@
RETURN_FALSE;
}
+ if (PG(safe_mode) && !php_checkuid(Z_STRVAL_PP(frompath), NULL,
CHECKUID_CHECK_FILE_AND_DIR)) {
+ RETURN_FALSE;
+ }
+
+ if (php_check_open_basedir(Z_STRVAL_PP(topath) TSRMLS_CC)) {
+ RETURN_FALSE;
+ }
+
+ if (php_check_open_basedir(Z_STRVAL_PP(frompath) TSRMLS_CC)) {
+ RETURN_FALSE;
+ }
+
if (!strncasecmp(Z_STRVAL_PP(topath), "http://", 7) ||
!strncasecmp(Z_STRVAL_PP(topath), "ftp://", 6)) {
php_error(E_WARNING, "Unable to symlink to a URL");
RETURN_FALSE;
@@ -143,6 +155,18 @@
convert_to_string_ex(frompath);
if (PG(safe_mode) && !php_checkuid(Z_STRVAL_PP(topath), NULL,
CHECKUID_CHECK_FILE_AND_DIR)) {
+ RETURN_FALSE;
+ }
+
+ if (PG(safe_mode) && !php_checkuid(Z_STRVAL_PP(frompath), NULL,
CHECKUID_CHECK_FILE_AND_DIR)) {
+ RETURN_FALSE;
+ }
+
+ if (php_check_open_basedir(Z_STRVAL_PP(topath) TSRMLS_CC)) {
+ RETURN_FALSE;
+ }
+
+ if (php_check_open_basedir(Z_STRVAL_PP(frompath) TSRMLS_CC)) {
RETURN_FALSE;
}