Bug #2821: safe_mode check bypassed by link/symlink

From: Date: Wed, 24 Nov 1999 16:39:54 +0000
Subject: Bug #2821: safe_mode check bypassed by link/symlink
Groups: php.dev 
Request: Send a blank email to php-dev+get-13060@lists.php.net to get a copy of this message
From: stas@zend.com Operating system: All PHP version: 3.0.12 PHP Bug Type: Misbehaving function Bug description: safe_mode check bypassed by link/symlink Let's imagine restricted user, that has chrooted FTP and safe-mode PHP. Can this user read other user's files? Yes, he can: <?php symlink(".","ww/ftp:"); chdir("ww"); symlink("ftp://../../secretfile.html","l"); $f=fopen("l","r"); fpassthru($f); ?> gives contents of secret_file, even though it isn't user-owned. the "ftp://" part breaks owner check for symlink, and "l" is allowed since "ww" is owned by current user. Note, that removing directory-check and checking only by UID will break all config-saving scripts...

« previous php.dev (#13060) next »