note 63390 added to features.safe-mode.functions
| From: | zauker at osu1 dot php dot net | Date: | Tue, 21 Mar 2006 22:57:20 +0000 |
| Subject: | note 63390 added to features.safe-mode.functions | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-106184@lists.php.net to get a copy of this message | ||
The SAFE_MODE handling of glob() needs a checkup for security reasons.
In short - always with SAFE_MODE on:
1) glob() can still fetch all filenames in a directory not owned by the
same UID as the user, if just the first file in the directory (or more
specific, the glob-pattern) happens to be owned by the same user as the
PHP-script.
2a) No warning is raised if glob is used on another owner's directory
and there is no match.
2b) In those cases where SAFE_MODE correctly prohibits glob() from
fetching a list of files, the warning still discloses the first
filename.
Solution: glob() in SAFE_MODE should be restricted in the same way as
opendir() is
see the link http://bugs.php.net/bug.php?id=28932
----
Server IP: 80.241.173.254
Probable Submitter: 217.133.63.65
----
X-Spam-Status: No, hits=3.1 required=5.0 tests=DATE_MISSING,FROM_NO_LOWER
autolearn=no version=2.64
----
Manual Page -- http://www.php.net/manual/en/features.safe-mode.functions.php
Edit -- http://master.php.net/note/edit/63390
Del: integrated -- http://master.php.net/note/delete/63390/integrated
Del: useless -- http://master.php.net/note/delete/63390/useless
Del: bad code -- http://master.php.net/note/delete/63390/bad+code
Del: spam -- http://master.php.net/note/delete/63390/spam
Del: non-english -- http://master.php.net/note/delete/63390/non-english
Del: in docs -- http://master.php.net/note/delete/63390/in+docs
Del: other reasons-- http://master.php.net/note/delete/63390
Reject -- http://master.php.net/note/reject/63390
Search -- http://master.php.net/manage/user-notes.php