Pretty mammoth security issue with safe_mode_exec

From: Date: Fri, 05 Jan 2001 12:11:11 +0000
Subject: Pretty mammoth security issue with safe_mode_exec
Groups: php.dev 
Request: Send a blank email to php-dev+get-43031@lists.php.net to get a copy of this message
If you have safe mode enabled, and have a safe mode exec directory, here's how you can execute binarys outside of your safe mode exec directory! Normally... system("../../../../../bin/cp blah blip"); would fail (as .. is blocked in _Exec (standard/exec.c) However... system("\.\./\.\./\.\./\.\./\.\./bin/cp blah blip"); will work fine! This is because the .. check was performed before the php_escape_shell_cmd in exec.c! --We fixed it, and our PHP *still* compiles :) (untested patch for exec.c attached) adamw adam@elysium.ltd.uk

Attachment: [application/octet-stream] php-4.0.4-system.patch
« previous php.dev (#43031) next »