Re: RE: (SRADV00001) Arbitrary file disclosure through PHP file upload

From: Date: Mon, 04 Sep 2000 22:35:03 +0000
Subject: Re: RE: (SRADV00001) Arbitrary file disclosure through PHP file upload
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-31985@lists.php.net to get a copy of this message
The initial fix published earlier did NOT fix the vulnerability that was discovered, and could also cause crashes under certain circumstances. It could also cause some applications to fail, due to a side effect that prevents certain valid form variables from being processed correctly. The correct, tested fixed file (without any side effects) is available at http://cvsweb.php.net/viewcvs.cgi/~checkout~/php4/main/rfc1867.c?rev=1.45&content-type=text/plain The diff against version 4.0.2 is available at: http://cvsweb.php.net/viewcvs.cgi/php4/main/rfc1867.c.diff?r1=1.38%3Aphp_4_0_2&tr1=1.1&r2=text&tr2=1.45&diff_format=u It is also attached to this message. Thanks to James Moore for helping me test this fix. Zeev

Attachment: [application/octet-stream] rfc1867.c.diff
« previous php.dev (#31985) next »