[Bug 305806] New: squirrelmail fortune plugin doesn't work
https://bugzilla.novell.com/show_bug.cgi?id=305806 Summary: squirrelmail fortune plugin doesn't work Product: openSUSE 10.3 Version: Beta 2 Platform: Other OS/Version: Other Status: NEW Severity: Minor Priority: P5 - None Component: Other AssignedTo: ltinkl@novell.com ReportedBy: poeml@novell.com QAContact: qa@suse.de CC: crrodriguez@novell.com Found By: --- Instead of a fortune, squirrelmail displays: Warning: is_file(): open_basedir restriction in effect. File(/usr/bin/fortune) is not within the allowed path(s): (/srv/www/htdocs/squirrelmail:/var/lib/squirrelmail:/usr/share/php5/PEAR:/tmp:/var/lib/php5) in /srv/www/htdocs/squirrelmail/plugins/fortune/setup.php on line 47 squirrelmail.conf is: php_admin_value open_basedir "/srv/www/htdocs/squirrelmail:/var/lib/squirrelmail:/usr/share/php5/PEAR:/tmp" Adding /usr/bin/fortune to the open_basedir setting does make it work. Dont know if this is the right thing. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=305806#c1
--- Comment #1 from Cristian Rodriguez
Dont know if this is the right thing.
It isnt ;) however as open_basedir is a weird thing, it works. is this plugin included into the distribution..? You have hitted one of the many open_basedir gotchas, to be correct in this case, you should add /usr/bin to open_basedir which pretty much mean that any PHP script can execute arbitrary binaries on your system :-( In short, open_basedir is no panacea and have a large number of issues, nothing replace proper OS level security. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=305806#c2
--- Comment #2 from Peter Poeml
https://bugzilla.novell.com/show_bug.cgi?id=305806
Lukas Tinkl
https://bugzilla.novell.com/show_bug.cgi?id=305806
Vladimir Nadvornik
https://bugzilla.novell.com/show_bug.cgi?id=305806#c3
Cristian Rodriguez
https://bugzilla.novell.com/show_bug.cgi?id=305806#c4
--- Comment #4 from Cristian Rodriguez
https://bugzilla.novell.com/show_bug.cgi?id=305806
User crrodriguez@novell.com added comment
https://bugzilla.novell.com/show_bug.cgi?id=305806#c5
Cristian Rodriguez
https://bugzilla.novell.com/show_bug.cgi?id=305806
User crrodriguez@novell.com added comment
https://bugzilla.novell.com/show_bug.cgi?id=305806#c6
Cristian Rodriguez
participants (1)
-
bugzilla_noreply@novell.com