Possible security issue with extension

From: Date: Wed, 03 Jan 2001 15:22:46 +0000
Subject: Possible security issue with extension
Groups: php.dev 
Request: Send a blank email to php-dev+get-42828@lists.php.net to get a copy of this message
Looking on the code of php_dl function (ext/standard/dl.c:94 on CVS), I see that the name of loaded library is formed from name of extension_dir with name of extension appended. No checks for .. and stuff are made. Is it not dangerous to allow user to load arbitrary .so's into the code? -- Stanislav Malyshev, Zend Products Engineer stas@zend.com http://www.zend.com/ +972-3-6139665 ext.115

« previous php.dev (#42828) next »