Re: PHP 4.0 Bug #2360: Chmod in safe mode allows setuid bits

From: Date: Thu, 01 Jan 1970 00:00:00 +0000
Subject: Re: PHP 4.0 Bug #2360: Chmod in safe mode allows setuid bits
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-11217@lists.php.net to get a copy of this message
> 1) use safe mode at all > 2) allow interactive logins on the Web server > 3) allow setuid execution of user-created files > > that would have any particular concern about this. At my site > conditions #1 and #2 hold but not #3, since we mount almost everything > no-setuid. But all I have to do is forget the no-setuid mount during > a system migration or upgrade and I've potentially allowed access I am > going to some trouble to avoid by using safe mode in the first place. Ah, right. Ok, I will have a look at fixing chmod(). There might not actually be any real good reason to allow chmod() under safe-mode at all. -Rasmus

« previous php.dev (#11217) next »