Re: Voulnerability in 3.*-4.*

From: Date: Sat, 08 Jan 2000 14:19:44 +0000
Subject: Re: Voulnerability in 3.*-4.*
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-14409@lists.php.net to get a copy of this message
On Sat, 8 Jan 2000 rasmus@php.net wrote: > Hrm.. Actually, now I am really confused. There is only one while loop > in that function and it is: > while(s && *(s+1)=='\0' && s>fn) { > s='\0'; > s = strrchr(fn,'/'); > } > > The filename /foo/foo/foo/blah does not have any trailing slashes and this > loop would not apply. Are you talking about some other loop? Yes, yes. But when strrchr() is runnnig (before the loop), it points to the /blah at the /foo/foo/blah (blah is a file). So, the next string is s='\0'; \0/blah. So, if You like to remove a file blah, You get the stat information for /foo/foo, I think, not for blah. If stat is sensitive for end_of_the_string, so.....

« previous php.dev (#14409) next »