Re: cvs: php4 / NEWS
| From: | Rasmus Lerdorf | Date: | Tue, 05 Sep 2000 01:40:05 +0000 |
| Subject: | Re: cvs: php4 / NEWS | ||
| References: | 1 | Groups: | php.cvs |
| Request: | Send a blank email to php-cvs+get-1567@lists.php.net to get a copy of this message | ||
> BTW, as far as I can tell, Rasmus's initial fix didn't work, as it
> protected $foo_name (which is the original file name, as it was typed in
> the form), as opposed to $foo, which is the name of the temporary file on
> the server (which users are likely to manipulate/display).
Didn't think so:
sprintf(lbuf, "%s_name[%s]", abuf, arr_index);
+ sbuf = estrdup(abuf);
abuf contains the 'foo' part not the full 'foo_name'.
Not that I tested the fix beyond typing in the exact exploit and testing
it against that. Doesn't really matter at this point. But we need to
address the second issue too.
-Rasmus