Re: Mail_Mbox 0.1.3

From: Date: Sun, 29 Dec 2002 04:26:17 +0000
Subject: Re: Mail_Mbox 0.1.3
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-11902@lists.php.net to get a copy of this message
I fixed tmp security with the following patch: --- mbox.php.umask 2002-12-29 01:23:29.000000000 -0300 +++ mbox.php 2002-12-29 01:19:17.000000000 -0300 @@ -316,14 +316,9 @@ return PEAR::raiseError("Message doesnt exists."); } - // changing umask for security reasons - $umaskOld = umask(077); // creating temp file - $ftempname = tempnam ("/tmp", rand(0, 9)); - // returning to old umask - umask($umaskOld); - - $ftemp = fopen($ftempname, "w"); + $ftempname = tempnam ("/tmp", rand(0, 9)); + $ftemp = fopen($ftempname, "w"); if ($ftemp == false) { return PEAR::raiseError("Cannot create a temp file. Cannot handle this error."); } I liked the URL format to get the data, but I need help to create the Mail_Store. If someone want to help in the code, I will appreceate. On Sun, 2002-12-29 at 00:02, Eric wrote: > There appears to be a security problem in the 0.1.4 release. Writing > files to '/tmp' without first setting the umask to a safe value is > dangerous on some platforms. This will create a race condition that may > expose the contents of a user's mailbox. > > As for the interface, i think the base class should only really include a > couple of functions, most notably an 'open()' function that will create an > object of the mail store type. For example: > > class Mail_Store { > function open($mailstorepath) { > parse path to determine mail store location and driver > something such as: > maildir://var/spool/username > mbox://var/spool/username > cyrus://var/spool/username > . > . > > switch ($drivername) { > case 'mbox': > return(Mail_Store_MBOX::open($filename)); > . > . > > } > } > } > > On 28 Dec 2002, Roberto [ISO-8859-1] Bertó wrote: > > > You can download the latest release and take a look on it. > > > > > > > > About Mail_Store thing If someone wants to help I guess we dont should > > make something unique but in each method (remove, update, get) we should > > have a differente code for each of 2 or 3 types (mbox, maildir) since > > the way it works is completly different, so, a $store = new > > Mail_Store("mbox") will be nice. > > > > > > But, I guess you could test Mail_Mbox before think in everything else. > > > > > > > > > > > > > > > > -- > > Roberto Bertó <roberto@desenvolve.com.br> > > Desenvolve Solucões de Internet > > > > > > -- > > PEAR Development Mailing List (http://pear.php.net/) > > To unsubscribe, visit: http://www.php.net/unsub.php > > > > -- Roberto Bertó <roberto@desenvolve.com.br> Desenvolve Solucões de Internet

« previous php.pear.dev (#11902) next »