Re: Mail_Mbox 0.1.3
| From: | Roberto Bertó | Date: | Sun, 29 Dec 2002 04:26:17 +0000 |
| Subject: | Re: Mail_Mbox 0.1.3 | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-11902@lists.php.net to get a copy of this message | ||
I fixed tmp security with the following patch:
--- mbox.php.umask 2002-12-29 01:23:29.000000000 -0300
+++ mbox.php 2002-12-29 01:19:17.000000000 -0300
@@ -316,14 +316,9 @@
return PEAR::raiseError("Message doesnt exists.");
}
- // changing umask for security reasons
- $umaskOld = umask(077);
// creating temp file
- $ftempname = tempnam ("/tmp", rand(0, 9));
- // returning to old umask
- umask($umaskOld);
-
- $ftemp = fopen($ftempname, "w");
+ $ftempname = tempnam ("/tmp", rand(0, 9));
+ $ftemp = fopen($ftempname, "w");
if ($ftemp == false) {
return PEAR::raiseError("Cannot create a temp file. Cannot
handle this error.");
}
I liked the URL format to get the data, but I need help to create the
Mail_Store. If someone want to help in the code, I will appreceate.
On Sun, 2002-12-29 at 00:02, Eric wrote:
> There appears to be a security problem in the 0.1.4 release. Writing
> files to '/tmp' without first setting the umask to a safe value is
> dangerous on some platforms. This will create a race condition that may
> expose the contents of a user's mailbox.
>
> As for the interface, i think the base class should only really include a
> couple of functions, most notably an 'open()' function that will create an
> object of the mail store type. For example:
>
> class Mail_Store {
> function open($mailstorepath) {
> parse path to determine mail store location and driver
> something such as:
> maildir://var/spool/username
> mbox://var/spool/username
> cyrus://var/spool/username
> .
> .
>
> switch ($drivername) {
> case 'mbox':
> return(Mail_Store_MBOX::open($filename));
> .
> .
>
> }
> }
> }
>
> On 28 Dec 2002, Roberto [ISO-8859-1] Bertó wrote:
>
> > You can download the latest release and take a look on it.
> >
> >
> >
> > About Mail_Store thing If someone wants to help I guess we dont should
> > make something unique but in each method (remove, update, get) we should
> > have a differente code for each of 2 or 3 types (mbox, maildir) since
> > the way it works is completly different, so, a $store = new
> > Mail_Store("mbox") will be nice.
> >
> >
> > But, I guess you could test Mail_Mbox before think in everything else.
> >
> >
> >
> >
> >
> >
> >
> > --
> > Roberto Bertó <roberto@desenvolve.com.br>
> > Desenvolve Solucões de Internet
> >
> >
> > --
> > PEAR Development Mailing List (http://pear.php.net/)
> > To unsubscribe, visit: http://www.php.net/unsub.php
> >
> >
--
Roberto Bertó <roberto@desenvolve.com.br>
Desenvolve Solucões de Internet