Re: PHP 4.0 Bug #7187 Updated: open_basedir is broken! Security alert!

From: Date: Fri, 13 Oct 2000 16:23:52 +0000
Subject: Re: PHP 4.0 Bug #7187 Updated: open_basedir is broken! Security alert!
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-34931@lists.php.net to get a copy of this message
It's probably the php_value issue. I've already contacted him On 13 Oct 2000, Bug Database wrote: > ID: 7187 > Updated by: andi > Reported By: dron@usa.net > Status: Open > Bug Type: PHP options/info functions > Assigned To: > Comments: > > You should be using full path with the open_basedir directive as far as I know. Can you please > try and let us know of the results? > > Previous Comments: > --------------------------------------------------------------------------- > > [2000-10-13 12:01:50] dron@usa.net > open_basedir is broken in 4.03 release!!! It is not working like in 4.02.. > I used > php_value open_basedir '.' > in 4.02 to restrict some virtual servers in apache to access external files, but after > upgrading to version 4.03 it is allow to access any file in filesystem. > Running apache 1.3.12 and php as a dynamic module. > Any hotfix? > > it MAY be connected with a Bug id #7175. > Please fix as soon as possible! > > --------------------------------------------------------------------------- > > [2000-10-13 11:52:51] dron@usa.net > open_basedir is broken in 4.03 release!!! It is not working like in 4.02.. > I used > php_value open_basedir '.' > in 4.02 to restrict some virtual servers in apache to access external files, but after > upgrading to version 4.03 it is allow to access any file in filesystem. > Running apache 1.3.12 and php as a dynamic module. > Any hotfix? > > --------------------------------------------------------------------------- > > > Full Bug description available at: http://bugs.php.net/?id=7187 > > > -- Zeev Suraski <zeev@zend.com> http://www.zend.com/

« previous php.dev (#34931) next »