Re: Voulnerability in 3.*-4.*
| From: | rasmus@php.net | Date: | Thu, 01 Jan 1970 00:00:00 +0000 |
| Subject: | Re: Voulnerability in 3.*-4.* | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-14405@lists.php.net to get a copy of this message | ||
> Hm... I cannot give You an access :).
> So, You can simply put some debug printfs in those places to discover the
> problem. Really, if everything is OK, the loop <while(....)> is not
> working for the filename, and the pointer s is at the same position as
> fna, so, at 0.
> for example, file name /foo/foo/foo/blah
> bypasses the <while> loop, when working under apache as a cgi(not a
> module) without changes.
Hrm.. Actually, now I am really confused. There is only one while loop
in that function and it is:
/* This loop gets rid of trailing slashes which could otherwise be
* used to confuse the function.
*/
while(s && *(s+1)=='\0' && s>fn) {
s='\0';
s = strrchr(fn,'/');
}
The filename /foo/foo/foo/blah does not have any trailing slashes and this
loop would not apply. Are you talking about some other loop?
-Rasmus