Bug #11570 Updated: Security Hole on ChDir()
| From: | rasmus@php.net | Date: | Wed, 20 Jun 2001 14:46:23 +0000 |
| Subject: | Bug #11570 Updated: Security Hole on ChDir() | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-57404@lists.php.net to get a copy of this message | ||
ID: 11570
Updated by: rasmus
Reported By: wangshui@nyist.net
Old-Status: Open
Status: Closed
Bug Type: Directory function related
Operating system:
PHP Version: 4.0.4pl1
Assigned To:
Comments:
Fixed in CVS
Previous Comments:
---------------------------------------------------------------------------
[2001-06-20 00:22:31] wangshui@nyist.net
ChDir() can be use to enter a directory which belongs to others. Hackers can use this hole to break
the SafeMode and OpenBaseDir restriction and enter and view and even open files in someone
else' directory.
In a multiuser environment where users must have some files with the same owner( such as
'nobody', to handle file-upload tasks), this hole is extremely dangerous.
---------------------------------------------------------------------------
ATTENTION! Do NOT reply to this email!
To reply, use the web interface found at http://bugs.php.net/?id=11570&edit=2