Re: cvs: php4 / NEWS
| From: | Rasmus Lerdorf | Date: | Tue, 05 Sep 2000 06:01:11 +0000 |
| Subject: | Re: cvs: php4 / NEWS | ||
| References: | 1 | Groups: | php.cvs |
| Request: | Send a blank email to php-cvs+get-1571@lists.php.net to get a copy of this message | ||
> At 04:40 05/09/2000, Rasmus Lerdorf wrote:
> > > BTW, as far as I can tell, Rasmus's initial fix didn't work, as it
> > > protected $foo_name (which is the original file name, as it was typed in
> > > the form), as opposed to $foo, which is the name of the temporary file on
> > > the server (which users are likely to manipulate/display).
> >
> >Didn't think so:
> >
> > sprintf(lbuf, "%s_name[%s]", abuf, arr_index);
> >+ sbuf = estrdup(abuf);
> >
> >abuf contains the 'foo' part not the full 'foo_name'.
> >
> >Not that I tested the fix beyond typing in the exact exploit and testing
> >it against that. Doesn't really matter at this point. But we need to
> >address the second issue too.
>
> Well, other than killing the exact exploit as-is, it was still possible to
> exploit PHP, and it also made it possible to crash PHP remotely on demand...
The same goes for the first three versions of your fix. Relax.
And even with your fix it is still exploitable.
-Rasmus