open_basedir bug also not fixed?

classic Classic list List threaded Threaded
2 messages Options
Reply | Threaded
Open this post in threaded view
|

open_basedir bug also not fixed?

thorben-2
Hello,
as described in [1], safemode bugs are not fixed in debian mod_php. is
it the same witch the open_basedir parameter? the bug described in [2]
also exists in currend PHP version of sarge. i know that open_base dir
makes  no  sense without safemode but i am writing a paper and I don't
want to write presumptions.


greetings
thorben

[1] http://lists.debian.org/debian-security/2005/07/msg00160.html
[2] http://bugs.php.net/bug.php?id=32937



--
To UNSUBSCRIBE, email to [hidden email]
with a subject of "unsubscribe". Trouble? Contact [hidden email]

Reply | Threaded
Open this post in threaded view
|

Re: open_basedir bug also not fixed?

Florian Weimer
> as described in [1], safemode bugs are not fixed in debian mod_php.

The document you quoted is unofficial.  As far as I know, it matches
existing practice (which is not official documented, unfortunately).

I think it would make sense to include a reference to open_basedir in
that documented, should it ever receive official status.  Thanks for
the suggestion.


--
To UNSUBSCRIBE, email to [hidden email]
with a subject of "unsubscribe". Trouble? Contact [hidden email]