Voulnerability in 3.*-4.*

From: Date: Sat, 08 Jan 2000 13:13:21 +0000
Subject: Voulnerability in 3.*-4.*
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-14399@lists.php.net to get a copy of this message
Hi! There is a problem with security in the file safe_mode.c (affects on functions, that use _php3_checkuid: unlink, rmdir....). So, the explanation. (UNIX, Apache, php3....) There is a string, like if (s) { *s='\0'; ret = stat(fn,&sb1); So, how it works: If mode < 3, then if (ret>-1) { uid=sb.st_uid; if (uid == _php3_getuid()) return(1); successfully bypass the test, if the uid of running php is not equal to uid of the tested file. Then, it goes to if(s), bypassing the loop while: while(s && *(s+1)=='\0' && s>fn) { s='\0'; s = strrchr(fn,'/'); } (filename is good, so the loop is not working). The next step - *s='\0'; ret = stat(fn,&sb); yes, it works, that results in: sb.st_uid == uid_of_the_running_process. So, any inclusion of unlink or rmdir can cause the situation(in some cases), when user can remove any file or directory, produced by any other user (_php3_checkuid returns 1, so, the safe mode is not working in functions, that are using _php3_checkuid). I do not know, what is the idea of *s='\0'; before stat(yes, it puts the end of the string to the beginning of the string) (who can explain this?), so, everything works more or less fine without it. Have a nice day!

« previous php.dev (#14399) next »