Re: PHP 4.0 Bug #2360: Chmod in safe mode allows setuid bits
| From: | Rasmus Lerdorf | Date: | Thu, 01 Jan 1970 00:00:00 +0000 |
| Subject: | Re: PHP 4.0 Bug #2360: Chmod in safe mode allows setuid bits | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-11217@lists.php.net to get a copy of this message | ||
> 1) use safe mode at all
> 2) allow interactive logins on the Web server
> 3) allow setuid execution of user-created files
>
> that would have any particular concern about this. At my site
> conditions #1 and #2 hold but not #3, since we mount almost everything
> no-setuid. But all I have to do is forget the no-setuid mount during
> a system migration or upgrade and I've potentially allowed access I am
> going to some trouble to avoid by using safe mode in the first place.
Ah, right. Ok, I will have a look at fixing chmod(). There might not
actually be any real good reason to allow chmod() under safe-mode at all.
-Rasmus