Re: Voulnerability in 3.*-4.*
| From: | vvs_php at nsrd dot npi dot msu dot su | Date: | Sat, 08 Jan 2000 14:19:44 +0000 |
| Subject: | Re: Voulnerability in 3.*-4.* | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-14409@lists.php.net to get a copy of this message | ||
On Sat, 8 Jan 2000 rasmus@php.net wrote:
> Hrm.. Actually, now I am really confused. There is only one while loop
> in that function and it is:
> while(s && *(s+1)=='\0' && s>fn) {
> s='\0';
> s = strrchr(fn,'/');
> }
>
> The filename /foo/foo/foo/blah does not have any trailing slashes and this
> loop would not apply. Are you talking about some other loop?
Yes, yes.
But when strrchr() is runnnig (before the loop), it points to the /blah at
the /foo/foo/blah (blah is a file). So, the next string is s='\0';
\0/blah. So, if You like to remove a file blah, You get the stat
information for /foo/foo, I think, not for blah. If stat is sensitive for
end_of_the_string, so.....