PHP 4.0 Bug #2360: Chmod in safe mode allows setuid bits

From: Date: Wed, 22 Sep 1999 20:30:12 +0000
Subject: PHP 4.0 Bug #2360: Chmod in safe mode allows setuid bits
Groups: php.dev 
Request: Send a blank email to php-dev+get-11213@lists.php.net to get a copy of this message
From: mic@uts.cc.utexas.edu Operating system: Digital Unix 4.0F PHP version: 4.0 Beta 2 PHP Bug Type: Misbehaving function Bug description: Chmod in safe mode allows setuid bits The chmod function can set the setuid bit on a file that the script has created. Since these files are owned by the Web server uid, even in safe mode you can create a setuid copy of /bin/sh using a PHP script and then use the setuid shell to access files as the Web server user. I can supply my test script upon request. This issue is a moot point when safe mode is not in effect, since then you can simply exec any shell command you want as the Web server uid. Sites that do use safe mode to restrict program execution under the Web server uid are more prone to the problem, and then only if they offer interactive login access and also have user-writable file systems that allow setuid program execution. This is a fairly small set of sites but it's probably nonempty. Chmod should probably not allow setuid bits when safe mode is in effect. Regards, Mic Kaczmarczik mic@uts.cc.utexas.edu

« previous php.dev (#11213) next »