[Bug 136651] PHP mixes up open_basedir settings
https://bugzilla.novell.com/show_bug.cgi?id=136651 ------- Comment #29 from suse-beta@cboltz.de 2006-11-03 17:14 MST ------- ping ;-) security team: when can fixed packages for this be expected? Note: This bug is really security relevant! Being unable to restrict open_basedir means that scripts from one vHost can modify data of any other vHost. Since I have running Typo3 (including file upload via PHP) on several vHosts, lots of files and directories are writeable by wwwrun - therefore the "no write permissions on filesystem level" argument unfortunately is not valid here. -> I'd vote for releasing the fix ASAP. Ales: Is it possible to make some test packages available? -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug, or are watching someone who is.
participants (1)
-
bugzilla_noreply@novell.com