Re: Voulnerability in 3.*-4.*

From: Date: Sat, 08 Jan 2000 14:27:33 +0000
Subject: Re: Voulnerability in 3.*-4.*
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-14418@lists.php.net to get a copy of this message
rasmus@php.net wrote: > > > Hm... I cannot give You an access :). > > So, You can simply put some debug printfs in those places to discover the > > problem. Really, if everything is OK, the loop <while(....)> is not > > working for the filename, and the pointer s is at the same position as > > fna, so, at 0. > > for example, file name /foo/foo/foo/blah > > bypasses the <while> loop, when working under apache as a cgi(not a > > module) without changes. > > Hrm.. Actually, now I am really confused. There is only one while loop > in that function and it is: > > /* This loop gets rid of trailing slashes which could otherwise be > * used to confuse the function. > */ > while(s && *(s+1)=='\0' && s>fn) { > s='\0'; > s = strrchr(fn,'/'); > } > > The filename /foo/foo/foo/blah does not have any trailing slashes and this > loop would not apply. Are you talking about some other loop? > Hold on a sec... isn't s a char* ? s='\0'; looks wrong to me. -- =========================================================================== Jim Jagielski [|] jim@jaguNET.com [|] http://www.jaguNET.com/ "Are you suggesting coconuts migrate??"

« previous php.dev (#14418) next »