Bug #11570: Security Hole on ChDir()
| From: | wangshui at nyist dot net | Date: | Wed, 20 Jun 2001 04:22:31 +0000 |
| Subject: | Bug #11570: Security Hole on ChDir() | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-57330@lists.php.net to get a copy of this message | ||
From: wangshui@nyist.net
Operating system: Linux
PHP version: 4.0.4pl1
PHP Bug Type: Directory function related
Bug description: Security Hole on ChDir()
ChDir() can be use to enter a directory which belongs to others. Hackers can use this hole to break
the SafeMode and OpenBaseDir restriction and enter and view and even open files in someone
else' directory.
In a multiuser environment where users must have some files with the same owner( such as
'nobody', to handle file-upload tasks), this hole is extremely dangerous.
--
Edit Bug report at: http://bugs.php.net/?id=11570&edit=1