Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 57180 - mod_php5 security problem (allow_url_fopen)
Summary: mod_php5 security problem (allow_url_fopen)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: New packages (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: PHP Bugs
URL:
Whiteboard:
Keywords:
: 57178 (view as bug list)
Depends on:
Blocks: 56963
  Show dependency tree
 
Reported: 2004-07-15 07:01 UTC by Tobias Luetke
Modified: 2004-08-07 12:32 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Tobias Luetke 2004-07-15 07:01:35 UTC
dispatch_conf wants to change my /etc/php/apache2-php5/php.ini like this :

 ; Whether to allow the treatment of URLs (like http:// or ftp://) as files.
-; allow_url_fopen = On
-; Closed for security - <robbat2@gentoo.org>
-allow_url_fopen = Off
+allow_url_fopen = On

I think we should honor robbat2's suggestion :)

Reproducible: Always
Steps to Reproduce:
1.
2.
3.
Comment 1 Martin Holzer (RETIRED) gentoo-dev 2004-07-15 07:12:03 UTC
*** Bug 57178 has been marked as a duplicate of this bug. ***
Comment 2 Robin Johnson archtester Gentoo Infrastructure gentoo-dev Security 2004-08-07 12:32:56 UTC
in cvs now.