Re: Voulnerability in 3.*-4.*
| From: | rasmus@php.net | Date: | Thu, 01 Jan 1970 00:00:00 +0000 |
| Subject: | Re: Voulnerability in 3.*-4.* | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-14402@lists.php.net to get a copy of this message | ||
> *s='\0';
> ret = stat(fn,&sb);
> yes, it works, that results in:
> sb.st_uid == uid_of_the_running_process.
>
> So, any inclusion of unlink or rmdir can cause the situation(in some
> cases), when user can remove any file or directory, produced by any other
> user (_php3_checkuid returns 1, so, the safe mode is not working in
> functions, that are using _php3_checkuid).
> I do not know, what is the idea of *s='\0'; before stat(yes, it puts the
> end of the string to the beginning of the string) (who can explain
> this?), so, everything works more or less fine without it.
Uh, not really. Look up above, I have:
s = strrchr(fn,'/');
That means that *s points to the last '/' in the fn string.
Therefore when I do:
*s='\0';
ret = stat(fn,&sb);
*s='/';
I am terminating the fn string at the last '/' and doing a stat on that
and then putting the '/' back where it belongs to restore the original fn
filename. So the *s='\0' before the stat() is quite important and you
can't just remove it. I am not saying that there isn't some bug, just
explaining why this was done this way. Perhaps you can give me a real
example of what exactly fails so I can try to track it down.
-Rasmus