Re: Voulnerability in 3.*-4.*

From: Date: Sat, 08 Jan 2000 14:03:04 +0000
Subject: Re: Voulnerability in 3.*-4.*
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-14403@lists.php.net to get a copy of this message
On Sat, 8 Jan 2000 rasmus@php.net wrote: > > I do not know, what is the idea of *s='\0'; before stat(yes, it puts the > > end of the string to the beginning of the string) (who can explain > > this?), so, everything works more or less fine without it. > > Uh, not really. Look up above, I have: > s = strrchr(fn,'/'); > That means that *s points to the last '/' in the fn string. > Therefore when I do: > *s='\0'; > ret = stat(fn,&sb); > *s='/'; > I am terminating the fn string at the last '/' and doing a stat on that > and then putting the '/' back where it belongs to restore the original fn > filename. So the *s='\0' before the stat() is quite important and you > can't just remove it. I am not saying that there isn't some bug, just > explaining why this was done this way. Perhaps you can give me a real > example of what exactly fails so I can try to track it down. Hm... I cannot give You an access :). So, You can simply put some debug printfs in those places to discover the problem. Really, if everything is OK, the loop <while(....)> is not working for the filename, and the pointer s is at the same position as fna, so, at 0. for example, file name /foo/foo/foo/blah bypasses the <while> loop, when working under apache as a cgi(not a module) without changes.

« previous php.dev (#14403) next »