Re: Voulnerability in 3.*-4.*
| From: | Jim Jagielski | Date: | Sat, 08 Jan 2000 14:27:33 +0000 |
| Subject: | Re: Voulnerability in 3.*-4.* | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-14418@lists.php.net to get a copy of this message | ||
rasmus@php.net wrote:
>
> > Hm... I cannot give You an access :).
> > So, You can simply put some debug printfs in those places to discover the
> > problem. Really, if everything is OK, the loop <while(....)> is not
> > working for the filename, and the pointer s is at the same position as
> > fna, so, at 0.
> > for example, file name /foo/foo/foo/blah
> > bypasses the <while> loop, when working under apache as a cgi(not a
> > module) without changes.
>
> Hrm.. Actually, now I am really confused. There is only one while loop
> in that function and it is:
>
> /* This loop gets rid of trailing slashes which could otherwise be
> * used to confuse the function.
> */
> while(s && *(s+1)=='\0' && s>fn) {
> s='\0';
> s = strrchr(fn,'/');
> }
>
> The filename /foo/foo/foo/blah does not have any trailing slashes and this
> loop would not apply. Are you talking about some other loop?
>
Hold on a sec... isn't s a char* ? s='\0'; looks wrong to me.
--
===========================================================================
Jim Jagielski [|] jim@jaguNET.com [|] http://www.jaguNET.com/
"Are you suggesting coconuts migrate??"