Voulnerability in 3.*-4.*
| From: | vvs_php at nsrd dot npi dot msu dot su | Date: | Sat, 08 Jan 2000 13:13:21 +0000 |
| Subject: | Voulnerability in 3.*-4.* | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-14399@lists.php.net to get a copy of this message | ||
Hi!
There is a problem with security in the file safe_mode.c (affects on
functions, that use _php3_checkuid: unlink, rmdir....).
So, the explanation. (UNIX, Apache, php3....)
There is a string, like
if (s) {
*s='\0';
ret = stat(fn,&sb1);
So, how it works:
If mode < 3, then
if (ret>-1) {
uid=sb.st_uid;
if (uid == _php3_getuid()) return(1);
successfully bypass the test, if the uid of running php is not equal to
uid of the tested file. Then, it goes to if(s), bypassing the loop while:
while(s && *(s+1)=='\0' && s>fn) {
s='\0';
s = strrchr(fn,'/');
}
(filename is good, so the loop is not working).
The next step -
*s='\0';
ret = stat(fn,&sb);
yes, it works, that results in:
sb.st_uid == uid_of_the_running_process.
So, any inclusion of unlink or rmdir can cause the situation(in some
cases), when user can remove any file or directory, produced by any other
user (_php3_checkuid returns 1, so, the safe mode is not working in
functions, that are using _php3_checkuid).
I do not know, what is the idea of *s='\0'; before stat(yes, it puts the
end of the string to the beginning of the string) (who can explain
this?), so, everything works more or less fine without it.
Have a nice day!