PHP 4.0 Bug #2360: Chmod in safe mode allows setuid bits
| From: | mic at uts dot cc dot utexas dot edu | Date: | Wed, 22 Sep 1999 20:30:12 +0000 |
| Subject: | PHP 4.0 Bug #2360: Chmod in safe mode allows setuid bits | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-11213@lists.php.net to get a copy of this message | ||
From: mic@uts.cc.utexas.edu
Operating system: Digital Unix 4.0F
PHP version: 4.0 Beta 2
PHP Bug Type: Misbehaving function
Bug description: Chmod in safe mode allows setuid bits
The chmod function can set the setuid bit on a file that the script has created. Since these files
are owned by the Web server uid, even in safe mode you can create a setuid copy of /bin/sh using a
PHP script and then use the setuid shell to access files as the Web server user. I can supply my
test script upon request.
This issue is a moot point when safe mode is not in effect, since then you can simply exec any shell
command you want as the Web server uid. Sites that do use safe mode to restrict program execution
under the Web server uid are more prone to the problem, and then only if they offer interactive
login access and also have user-writable file systems that allow setuid program execution. This is
a fairly small set of sites but it's probably nonempty.
Chmod should probably not allow setuid bits when safe mode is in effect.
Regards,
Mic Kaczmarczik
mic@uts.cc.utexas.edu