Bug #11570 Updated: Security Hole on ChDir()

From: Date: Wed, 20 Jun 2001 14:46:23 +0000
Subject: Bug #11570 Updated: Security Hole on ChDir()
Groups: php.dev 
Request: Send a blank email to php-dev+get-57404@lists.php.net to get a copy of this message
ID: 11570 Updated by: rasmus Reported By: wangshui@nyist.net Old-Status: Open Status: Closed Bug Type: Directory function related Operating system: PHP Version: 4.0.4pl1 Assigned To: Comments: Fixed in CVS Previous Comments: --------------------------------------------------------------------------- [2001-06-20 00:22:31] wangshui@nyist.net ChDir() can be use to enter a directory which belongs to others. Hackers can use this hole to break the SafeMode and OpenBaseDir restriction and enter and view and even open files in someone else' directory. In a multiuser environment where users must have some files with the same owner( such as 'nobody', to handle file-upload tasks), this hole is extremely dangerous. --------------------------------------------------------------------------- ATTENTION! Do NOT reply to this email! To reply, use the web interface found at http://bugs.php.net/?id=11570&edit=2

« previous php.dev (#57404) next »