Re: Voulnerability in 3.*-4.*

From: Date: Thu, 01 Jan 1970 00:00:00 +0000
Subject: Re: Voulnerability in 3.*-4.*
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-14410@lists.php.net to get a copy of this message
> > I don't need access, just a little PHP example script that causes the > > problem. So, you are saying that: > > > > <? > > unlink("/foo/foo/foo/blah"); > > ?> > yes, like so. > Also, try to compile and run: > -------------------------------------------- > #include <stdio.h> > #include <unistd.h> > #include <sys/stat.h> > > char fn[]="/foo/foo/foo/blah"; > main() > { > char *s; > > s = (char*)strrchr(fn,'/'); > > while(s && *(s+1)=='\0' && s>fn) { > s='\0'; > s = (char*)strrchr(fn,'/'); > printf("Mamma\n"); > } > } > --------------------- > Can You see Mamma on output? > And try to put "/" at the end of fn.... Ah, right, so the bug is simply that it should be *s='\0'; inside the loop there. Silly typo. -Rasmus

« previous php.dev (#14410) next »