Re: Voulnerability in 3.*-4.*
| From: | vvs_php at nsrd dot npi dot msu dot su | Date: | Sat, 08 Jan 2000 14:03:04 +0000 |
| Subject: | Re: Voulnerability in 3.*-4.* | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-14403@lists.php.net to get a copy of this message | ||
On Sat, 8 Jan 2000 rasmus@php.net wrote:
> > I do not know, what is the idea of *s='\0'; before stat(yes, it puts the
> > end of the string to the beginning of the string) (who can explain
> > this?), so, everything works more or less fine without it.
>
> Uh, not really. Look up above, I have:
> s = strrchr(fn,'/');
> That means that *s points to the last '/' in the fn string.
> Therefore when I do:
> *s='\0';
> ret = stat(fn,&sb);
> *s='/';
> I am terminating the fn string at the last '/' and doing a stat on that
> and then putting the '/' back where it belongs to restore the original fn
> filename. So the *s='\0' before the stat() is quite important and you
> can't just remove it. I am not saying that there isn't some bug, just
> explaining why this was done this way. Perhaps you can give me a real
> example of what exactly fails so I can try to track it down.
Hm... I cannot give You an access :).
So, You can simply put some debug printfs in those places to discover the
problem. Really, if everything is OK, the loop <while(....)> is not
working for the filename, and the pointer s is at the same position as
fna, so, at 0.
for example, file name /foo/foo/foo/blah
bypasses the <while> loop, when working under apache as a cgi(not a
module) without changes.