Re: Voulnerability in 3.*-4.*

From: Date: Thu, 01 Jan 1970 00:00:00 +0000
Subject: Re: Voulnerability in 3.*-4.*
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-14402@lists.php.net to get a copy of this message
> *s='\0'; > ret = stat(fn,&sb); > yes, it works, that results in: > sb.st_uid == uid_of_the_running_process. > > So, any inclusion of unlink or rmdir can cause the situation(in some > cases), when user can remove any file or directory, produced by any other > user (_php3_checkuid returns 1, so, the safe mode is not working in > functions, that are using _php3_checkuid). > I do not know, what is the idea of *s='\0'; before stat(yes, it puts the > end of the string to the beginning of the string) (who can explain > this?), so, everything works more or less fine without it. Uh, not really. Look up above, I have: s = strrchr(fn,'/'); That means that *s points to the last '/' in the fn string. Therefore when I do: *s='\0'; ret = stat(fn,&sb); *s='/'; I am terminating the fn string at the last '/' and doing a stat on that and then putting the '/' back where it belongs to restore the original fn filename. So the *s='\0' before the stat() is quite important and you can't just remove it. I am not saying that there isn't some bug, just explaining why this was done this way. Perhaps you can give me a real example of what exactly fails so I can try to track it down. -Rasmus

« previous php.dev (#14402) next »