Bug #12178 Updated: ext/standard/mail.c insecurity

From: Date: Fri, 30 Nov 2001 09:26:07 +0000
Subject: Bug #12178 Updated: ext/standard/mail.c insecurity
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-72110@lists.php.net to get a copy of this message
ID: 12178 Updated by: derick Reported By: sintes@nfrance.com Old Status: Open Status: Closed Bug Type: Mail related Operating System: All UNIX PHP Version: 4.0.6 New Comment: This was fixed a long time ago. (on 2001/07/05 08:47:37) Previous Comments: ------------------------------------------------------------------------ [2001-07-15 13:14:46] sintes@nfrance.com ext/standard/mail.c is potentialy insecure. >extra_cmd = (*argv[4])->value.str.val; >strcat (sendmail_cmd, extra_cmd); >sendmail = popen(sendmail_cmd, "w"); So it is possible to use extra_cmd to gain shell access. ------------------------------------------------------------------------ Edit this bug report at http://bugs.php.net/?id=12178&edit=1

« previous php.dev (#72110) next »