Red Hat Bugzilla – Bug 17245
upload form could be used to read any file on a system
Last modified: 2008-05-01 11:37:58 EDT
as explained on http://bugs.php.net/bugs.php?id=6496, a bug on the
generation of internal variables of PHP could be used to read any file on a
system (now on bugtraq)
php-4.0.2 is affected and previous versions should be also (tested on RC2
the attached patch fixes the problem.
upgrade to php-4.0.2 is a good idea too, spec on bug 17171 should be used
Created attachment 3239 [details]
patch for upload bug, build from zeev instructions on bugzilla
An errata is being prepped.
Hang on -- the bug is only a problem on poorly-coded pages, and the fix in CVS
appears to actually break certain other things which it's not supposed to (which
looks like it might actually be a problem in the hash table implementation in
obsoleted by 18965.
this patch is *somehow* included on 4.0.3pl1