PHP 4.0 Bug #7187 Updated: open_basedir is broken! Security alert!
| From: | Bug Database | Date: | Fri, 13 Oct 2000 16:20:35 +0000 |
| Subject: | PHP 4.0 Bug #7187 Updated: open_basedir is broken! Security alert! | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-34930@lists.php.net to get a copy of this message | ||
ID: 7187
Updated by: andi
Reported By: dron@usa.net
Status: Open
Bug Type: PHP options/info functions
Assigned To:
Comments:
You should be using full path with the open_basedir directive as far as I know. Can you please try
and let us know of the results?
Previous Comments:
---------------------------------------------------------------------------
[2000-10-13 12:01:50] dron@usa.net
open_basedir is broken in 4.03 release!!! It is not working like in 4.02..
I used
php_value open_basedir '.'
in 4.02 to restrict some virtual servers in apache to access external files, but after
upgrading to version 4.03 it is allow to access any file in filesystem.
Running apache 1.3.12 and php as a dynamic module.
Any hotfix?
it MAY be connected with a Bug id #7175.
Please fix as soon as possible!
---------------------------------------------------------------------------
[2000-10-13 11:52:51] dron@usa.net
open_basedir is broken in 4.03 release!!! It is not working like in 4.02..
I used
php_value open_basedir '.'
in 4.02 to restrict some virtual servers in apache to access external files, but after upgrading to
version 4.03 it is allow to access any file in filesystem.
Running apache 1.3.12 and php as a dynamic module.
Any hotfix?
---------------------------------------------------------------------------
Full Bug description available at: http://bugs.php.net/?id=7187