Re: PHP 4.0 Bug #7187 Updated: open_basedir is broken! Security alert!
| From: | Zeev Suraski | Date: | Fri, 13 Oct 2000 16:23:52 +0000 |
| Subject: | Re: PHP 4.0 Bug #7187 Updated: open_basedir is broken! Security alert! | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-34931@lists.php.net to get a copy of this message | ||
It's probably the php_value issue. I've already contacted him
On 13 Oct 2000, Bug Database wrote:
> ID: 7187
> Updated by: andi
> Reported By: dron@usa.net
> Status: Open
> Bug Type: PHP options/info functions
> Assigned To:
> Comments:
>
> You should be using full path with the open_basedir directive as far as I know. Can you please
> try and let us know of the results?
>
> Previous Comments:
> ---------------------------------------------------------------------------
>
> [2000-10-13 12:01:50] dron@usa.net
> open_basedir is broken in 4.03 release!!! It is not working like in 4.02..
> I used
> php_value open_basedir '.'
> in 4.02 to restrict some virtual servers in apache to access external files, but after
> upgrading to version 4.03 it is allow to access any file in filesystem.
> Running apache 1.3.12 and php as a dynamic module.
> Any hotfix?
>
> it MAY be connected with a Bug id #7175.
> Please fix as soon as possible!
>
> ---------------------------------------------------------------------------
>
> [2000-10-13 11:52:51] dron@usa.net
> open_basedir is broken in 4.03 release!!! It is not working like in 4.02..
> I used
> php_value open_basedir '.'
> in 4.02 to restrict some virtual servers in apache to access external files, but after
> upgrading to version 4.03 it is allow to access any file in filesystem.
> Running apache 1.3.12 and php as a dynamic module.
> Any hotfix?
>
> ---------------------------------------------------------------------------
>
>
> Full Bug description available at: http://bugs.php.net/?id=7187
>
>
>
--
Zeev Suraski <zeev@zend.com>
http://www.zend.com/