Bug #12255: (In safe mode) The UID check in chdir don't test the good directory

From: Date: Thu, 19 Jul 2001 14:55:20 +0000
Subject: Bug #12255: (In safe mode) The UID check in chdir don't test the good directory
Groups: php.dev 
Request: Send a blank email to php-dev+get-60305@lists.php.net to get a copy of this message
From: benoit@proxad.net Operating system: Debian GNU/Linux sid PHP version: 4.0.6 PHP Bug Type: Directory function related Bug description: (In safe mode) The UID check in chdir don't test the good directory In safe mode, when you chdir a specific directory, it does not test the UID of directory but the UID of the directory below. Let's say we do a chdir ("/home/benoit"); In safe mode, it will test the UID of /home against the one of the script so it fails. If we do a chdir ("/home/benoit/."); , PHP test the UID of /home/benoit/ against the UID of the script and succeed. But, logically, the two commands should succeed the same way. I think it's related to the code in "ext/standard/dir.c" around line 286 : > if (PG(safe_mode) && !php_checkuid((*arg)->value.str.val, NULL, CHECKUID_ALLOW_ONLY_DIR)) { and the way php_checkuid handle CHECKUID_ALLOW_ONLY_DIR. -- Edit bug report at: http://bugs.php.net/?id=12255&edit=1

« previous php.dev (#60305) next »