Bug #5920: strange use of open_basedir string
| From: | karel at econnect dot cz | Date: | Wed, 02 Aug 2000 11:03:40 +0000 |
| Subject: | Bug #5920: strange use of open_basedir string | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-27427@lists.php.net to get a copy of this message | ||
From: karel@econnect.cz
Operating system: Redhat 6.1
PHP version: 3.0.16
PHP Bug Type: Other
Bug description: strange use of open_basedir string
Example from php3.ini:
open_basedir = /home/www/test/no_such_dir
If there is no subdirectory named no_such_dir
on the filesystem, one would except that PHP does not
allow to open any files. But PHP allows to open files
within /home/www/test.
In other words PHP uses the longest substring from
open_basedir that represents a valid directory name.
This can cause security problem.
I did not test doc_root or other similar lines in php3.ini,
that could suffer the same problem.