PHP 4.0 Bug #7217: Security Problem with "include_dir" configuration

From: Date: Sun, 15 Oct 2000 07:49:55 +0000
Subject: PHP 4.0 Bug #7217: Security Problem with "include_dir" configuration
Groups: php.dev 
Request: Send a blank email to php-dev+get-35038@lists.php.net to get a copy of this message
From: afader@asqnet.org Operating system: linux PHP version: 4.0.2 PHP Bug Type: Feature/Change Request Bug description: Security Problem with "include_dir" configuration Okay - set up a common script directory. /home/httpd/phpi in php.ini - set include_dir = .:/home/httpd/phpi set safe_mode on. Put a file into the directory. Call it "counter.inc" make the owner of counter.inc any user and any group. make a web page with a different user in the same group. the web page cannot include("counter.inc"); you get a warning: SAFE MODE that uid 1 <> uid 2. This makes it impossible to have shared php includes across multiple users. - REQUEST - Allow some way for SAFE MODE to ignore user matching on a selected directory (or set of directories.) Or ignore matching for a specific userid/or/groupid on the target files??? Or, let me know what I'm doing wrong??? - Thanks - Alexander p.s. PHP rules ;-) -- Edit Bug report at: http://bugs.php.net/?id=7217&edit=1

« previous php.dev (#35038) next »